CVE-2002-2412: Low severity Nullsoft Winamp vulnerability
Winamp 2.80 stores authentication credentials in plaintext in the (1) [HTTP-AUTH] and (2) [winamp] sections in winamp.ini, which allows local users to gain access to other accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2412?
CVE-2002-2412 is considered a medium severity vulnerability due to the exposure of sensitive authentication credentials.
How do I fix CVE-2002-2412?
To mitigate CVE-2002-2412, users should avoid using Winamp 2.80 or upgrade to a newer version that does not store credentials in plaintext.
What platform is affected by CVE-2002-2412?
CVE-2002-2412 specifically affects Winamp version 2.80 on Windows operating systems.
Who is impacted by CVE-2002-2412?
Local users on the same machine can exploit CVE-2002-2412 to access stored authentication credentials from Winamp.
What can attackers do with CVE-2002-2412?
Attackers can gain unauthorized access to other user accounts by retrieving plaintext credentials from the winamp.ini file.