CVE-2002-1848: Low severity TightVNC TightVnc vulnerability
Published Dec 31, 2002
·Updated
TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords.
Affected Software
4 affected components
TightVNC TightVnc=1.2
TightVNC TightVnc=1.2.1
TightVNC TightVnc=1.2.2
TightVNC TightVnc=1.2.3
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jun 28, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1848?
CVE-2002-1848 is considered to be of moderate severity due to the risk of local password exposure.
2
How do I fix CVE-2002-1848?
To fix CVE-2002-1848, upgrade to TightVNC version 1.2.4 or later where this vulnerability is resolved.
3
Who is affected by CVE-2002-1848?
Users of TightVNC versions 1.2, 1.2.1, 1.2.2, and 1.2.3 running on Windows are affected by CVE-2002-1848.
4
What kind of data is exposed in CVE-2002-1848?
CVE-2002-1848 exposes unencrypted passwords stored in the password text control of the WinVNC Properties dialog.
5
Is CVE-2002-1848 a remote access vulnerability?
CVE-2002-1848 is not a remote access vulnerability; it requires local user access to exploit.