CVE Vulnerabilities

CVE-2002-1676

Published: Dec 31, 2002 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

BindView NetInventory 1.0, when used with NetRC 1.0, allows local users to read sensitive information (passwords) by deleting the HOSTCFG._NI file and forcing an audit, which rewrites the HOSTCFG._NI to HOSTCFG.INI and stores the passwords in cleartext until the audit is complete.

Affected Software

Name Vendor Start Version End Version
Netinventory Bindview 1.0 (including) 1.0 (including)
Netrc Bindview 1.0 (including) 1.0 (including)

References