CVE Vulnerabilities

CVE-2005-2898

Published: Sep 14, 2005 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

NOTE: this issue has been disputed by the vendor. FileZilla 2.2.14b and 2.2.15, and possibly earlier versions, when Use secure mode is disabled, uses a weak encryption scheme to store the users password in the configuration settings file, which allows local users to obtain sensitive information. NOTE: the vendor has disputed the issue, stating that the problem is not a vulnerability at all, but in fact a fundamental issue of every single program that can store passwords transparently.

Affected Software

Name Vendor Start Version End Version
Filezilla Filezilla 2.2.14b (including) 2.2.14b (including)
Filezilla Filezilla 2.2.15 (including) 2.2.15 (including)

References