J-Security Center

Title: UltraEdit FTP Client Weak Password Encryption Vulnerability

Severity: MODERATE

Description:

UltraEdit is a multi-featured commercial text editor with support for HTML, C/C++, VB, Java, Perl, XML, and C#. It also includes a hex editor and a small FTP client.

When a user accesses an FTP site using UltraEdit's FTP client they will be prompted to have the system remember FTP passwords for later use. When passwords are remembered they will be stored in a file called 'uedit32.ini' using an "admittedly" weak encryption algorithm. As a result, it is a fairly trivial task to decrypt the passwords for FTP accounts.

Successful exploitation of this vulnerability will allow a local attacker to gain unauthorized access to the FTP sites used by other local users.

Affected Products:

  • IDM Computer Solutions Inc UltraEdit-32 8.2.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.