First published: Wed May 29 2002(Updated: )
Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gaim | =0.57 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0377 is considered a high severity vulnerability due to the exposure of sensitive information.
To fix CVE-2002-0377, upgrade to a newer version of Gaim that addresses this vulnerability.
CVE-2002-0377 specifically affects Gaim version 0.57.
CVE-2002-0377 is a local information disclosure vulnerability.
CVE-2002-0377 cannot be exploited remotely as it requires local access to the machine running Gaim.