MiraMail stores authentication information in plaintext in .ini file

miramail-plaintext-auth-info (7855) The risk level is classified as MediumMedium Risk

Description:

MiraMail stores POP account usernames and passwords, user accounts, and groups in an .ini file in plaintext. A local attacker with access to the MiraMail installation directory could access this file to obtain usernames and passwords or add new user and group accounts.


Consequences:

Obtain Information

Remedy:

Upgrade to the latest version of MiraMail (1.05 or later), when it becomes available from the Nevrona Designs Web site. See References.

References:

  • BugTraq Mailing List, Wed Jan 09 2002 - 15:45:42 CST: MiraMail 1.04 can give POP account access and details.
  • Nevrona Designs Web site: MiraMail Message System.
  • BID-3843: Nevrona MiraMail Sensitive File Plain Text Storage Vulnerability
  • CVE-2002-0110: Nevrona Designs MiraMail 1.04 and earlier stores authentication information such as POP usernames and passwords in plaintext in a .ini file, which allows an attacker to gain privileges by reading the passwords from the file.
  • OSVDB ID: 14298: Nevrona Designs MiraMail .ini File Cleartext Authentication Credential Disclosure
  • US-CERT VU#245707: Nevrona Designs MiraMail stores all configuration and user account information in unencrypted text file

Platforms Affected:

  • Nevrona Designs MiraMail 1.04

Reported:

Jan 09, 2002

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email ignore thisxforceignore this@ignore thisus.ignore thisibm.comignore this

Return to the main page