PT-2001-2213 · Red Hat · Qpopper
Publicado
2001-08-31
·
Atualizado
2017-12-19
·
CVE-2001-1068
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
qpopper version 4.01
Description
The issue allows remote attackers to determine valid usernames on the system by generating different error messages when an invalid username is provided instead of a valid name. This occurs on Red Hat systems with qpopper 4.01 that uses PAM based authentication.
Recommendations
For qpopper version 4.01, consider modifying the authentication mechanism to provide uniform error messages for both valid and invalid usernames to prevent attackers from determining valid usernames.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Qpopper