First published: Fri May 03 2002(Updated: )
Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Messenger | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-0322 is considered high due to the potential for remote attackers to intercept cleartext passwords.
To fix CVE-2002-0322, upgrade to a later version of Yahoo Messenger that does not transmit passwords in cleartext.
CVE-2002-0322 exposes users to sniffing attacks where attackers can capture sensitive information like passwords.
Yes, all users of Yahoo Messenger 4.0 are vulnerable to CVE-2002-0322 as it affects the software's basic functionality.
While Yahoo Messenger is no longer widely used, vulnerabilities like CVE-2002-0322 are relevant as they highlight the risks of cleartext password transmission.