CVE-2002-0344: Medium severity symantec liveupdate vulnerability
Published May 3, 2002
·Updated
Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.
Affected Software
1 affected component
Symantec LiveUpdate<=1.5
Remediation
Patch Available
Patch Available
Event History
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0344?
CVE-2002-0344 is considered a high severity vulnerability due to the exposure of sensitive information in cleartext.
2
How do I fix CVE-2002-0344?
To fix CVE-2002-0344, update to a later version of Symantec LiveUpdate beyond 1.5 that does not store credentials in cleartext.
3
What type of information is exposed in CVE-2002-0344?
CVE-2002-0344 exposes usernames and passwords stored in cleartext in the Windows registry.
4
Which versions of Symantec LiveUpdate are affected by CVE-2002-0344?
CVE-2002-0344 affects Symantec LiveUpdate version 1.5 and earlier.
5
How can CVE-2002-0344 allow remote attackers to exploit systems?
CVE-2002-0344 allows remote attackers to impersonate the LiveUpdate server by accessing the stored credentials.