Vulnerability Name: | CVE-2002-2066 (CCN-7953) | ||||||||
Assigned: | 2002-01-21 | ||||||||
Published: | 2002-01-21 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | BestCrypt BCWipe 1.0.7 and 2.0 through 2.35.1 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2002-2066 Source: MITRE Type: CNA CVE-2002-2067 Source: MITRE Type: CNA CVE-2002-2068 Source: MITRE Type: CNA CVE-2002-2069 Source: MITRE Type: CNA CVE-2002-2070 Source: CONFIRM Type: Patch http://www.bcwipe.com/ Source: CCN Type: CIAC Information Bulletin M-034 Window File Wiping Utilities Miss Alternate Data Streams Source: CIAC Type: Vendor Advisory M-034 Source: XF Type: UNKNOWN ntfs-ads-file-wipe(7953) Source: CCN Type: OSVDB ID: 60043 BCWipe Windows Alternatve Data Stream Information Disclosure Source: CCN Type: OSVDB ID: 60044 East-Tec Eraser 2002 Windows Alternatve Data Stream Information Disclosure Source: CCN Type: OSVDB ID: 60045 Sami Tolvanen Eraser Windows Alternatve Data Stream Information Disclosure Source: CCN Type: OSVDB ID: 60046 PGP Data Wipe Windows Alternatve Data Stream Information Disclosure Source: CCN Type: OSVDB ID: 60047 SecureClean Windows Alternatve Data Stream Information Disclosure Source: BUGTRAQ Type: UNKNOWN 20020120 KSSA-003 - Multiple windows file wiping utilities do not properly wipe data with NTFS Source: BID Type: UNKNOWN 3912 Source: CCN Type: BID-3912 Multiple Vendor NTFS File Wipe Vulnerability Source: CCN Type: Kurt Seifried Security Advisory 003 (KSSA-003) Multiple windows file wiping utilities do not properly wipe data with NTFS file systems. Source: MISC Type: Vendor Advisory http://www.seifried.org/security/advisories/kssa-003.html Source: XF Type: UNKNOWN ntfs-ads-file-wipe(7953) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |