CVE Vulnerabilities

CVE-2002-2066

Incomplete Cleanup

Published: Dec 31, 2002 | Modified: Feb 08, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

BestCrypt BCWipe 1.0.7 and 2.0 through 2.35.1 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Bcwipe Jetico 2.0 (including) 2.35.1 (including)
Bcwipe Jetico 1.0.7 (including) 1.0.7 (including)

Potential Mitigations

References