Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:20887
HistoryNov 19, 2008 - 12:00 a.m.

Outdated and vulnerable OpenSource libraries used in "Deutsche Telekom" home banking software

2008-11-1900:00:00
vulners.com
25

The "Deutsche Telekom" resp. their "T-Online" branch offer their
own home banking software for Windows under
<ftp://software.t-online.de/pub/service/banking/banking70.exe&gt;
The current release is version 7.00.0004 from 2008-03-17.

This software is but insecure; it installs and uses:

To put the icing on the cake:

The vendor has been informed via its own hotline, its own CERT, its
press spokesman for security (the "Deutsche Telekom" is member of
the german initiative "Sicher im Netz", see
<https://www.sicher-im-netz.de/wir_ueber_uns/146.aspx&gt;&#41; and its
security officer, both per mail and phone (where available).

Response(s): NONE
Reaction(s): NONE

Stefan Kanthak

PS: <http://service.t-online.de/c/12/70/85/92/12708592.html&gt;
states that this software has been evaluated by TUeV Saarland and
got their label "TUeV Saarland: Gepruefte Home-Banking Software".
Whatever they checked: it wasn't the security of this software!