PT-2001-2213 · Red Hat · Qpopper

Publicado

2001-08-31

·

Atualizado

2017-12-19

·

CVE-2001-1068

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions qpopper version 4.01
Description The issue allows remote attackers to determine valid usernames on the system by generating different error messages when an invalid username is provided instead of a valid name. This occurs on Red Hat systems with qpopper 4.01 that uses PAM based authentication.
Recommendations For qpopper version 4.01, consider modifying the authentication mechanism to provide uniform error messages for both valid and invalid usernames to prevent attackers from determining valid usernames.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1068

Produtos afetados

Qpopper