First published: Fri Oct 04 2002(Updated: )
The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nCipher | ||
nCipher |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0941 is classified as a medium severity vulnerability due to the potential for privilege escalation.
To mitigate CVE-2002-0941, upgrade to a version of nCipher that is not affected by this vulnerability.
CVE-2002-0941 affects nCipher's TrustedCodeTool and possibly other applications utilizing the ConsoleCallBack class.
CVE-2002-0941 allows privilege escalation by leaking a passphrase when the user aborts an application prompt for the passphrase.
CVE-2002-0941 affects nCipher running specifically under JRE 1.4.0 and 1.4.0_01.