CVE-2001-0549: Medium severity Symantec LiveUpdate vulnerability
Published Aug 14, 2001
·Updated
Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords.
Affected Software
1 affected component
Symantec LiveUpdate=1.5
Remediation
Patch Available
Event History
Aug 14, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0549?
CVE-2001-0549 is considered a moderate severity vulnerability due to the potential for local users to obtain sensitive proxy passwords.
2
How do I fix CVE-2001-0549?
To fix CVE-2001-0549, it is recommended to upgrade to a version of Symantec LiveUpdate that does not store proxy passwords in cleartext.
3
Who is affected by CVE-2001-0549?
CVE-2001-0549 affects users of Symantec LiveUpdate version 1.5.
4
What does CVE-2001-0549 expose to local users?
CVE-2001-0549 exposes proxy passwords stored in cleartext in a registry key to local users.
5
Is there a workaround for CVE-2001-0549?
A temporary workaround for CVE-2001-0549 includes restricting access to the registry keys where the proxy passwords are stored.