CVE
- Id
- 1636
- CVE No.
- CVE-2000-0058
- Status
- Candidate
- Description
- Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.
- Phase
- Proposed (20000125)
- Votes
- MODIFY(2) Baker, Frech | NOOP(1) Christey
- Comments
- Frech> XF:handspring-visor-auth(3873) | Consider removing the security-express.com reference, since it is identical | to the BugTraq reference. The BugTraq reference is (hopefully) not going to | disappear soon, and the security-express.com reference provides no new or | additional information. | Christey> URLs will begin to be included with candidates to support | Board members" voting activities. They will be converted to | the generalized reference format when if candidate is | ACCEPTed and becomes an official entry. | Christey> The problem may not be a lack of authentication (as mentioned | by the poster), but rather weak authentication (the apparent | need to provide the same username). | Baker> MOdify description to indicate the weak authentication