CVE
- Id
- 1798
- CVE No.
- CVE-2000-0220
- Status
- Candidate
- Description
- ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.
- Phase
- Proposed (20000322)
- Votes
- ACCEPT(1) Armstrong | MODIFY(1) Frech | NOOP(5) Baker, Cole, LeBlanc, Ozancin, Wall | REJECT(1) Blake | REVIEWING(1) Levy
- Comments
- Blake> Discussion on Bugtraq shows that this is a really marginal issue. Very | tough to come up with a viable attack scenario. Also, it"s part of how | this class of software works, not a flaw in the cited package. Might be | possible to recast this into something more generic.... | Frech> XF:zonealarm-exposes-info