PT-2012-3351 · Atheme · Atheme
William Pitcock
·
Publicado
2012-10-01
·
Atualizado
2013-04-05
·
CVE-2012-1576
CVSS v2.0
6.0
Média
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Atheme versions 5.x through 5.2.6
Atheme versions 6.x through 6.0.9
Atheme versions 7.x through 7.0.0-beta1
Description
The issue arises from the
myuser delete function in libathemecore/account.c, which fails to properly clean up CertFP entries when a user is deleted. This allows remote attackers to access a different user account or cause a denial of service, resulting in a daemon crash, by logging in as a deleted user.Recommendations
For Atheme versions 5.x through 5.2.6, update to version 5.2.7 or later.
For Atheme versions 6.x through 6.0.9, update to version 6.0.10 or later.
For Atheme versions 7.x through 7.0.0-beta1, update to version 7.0.0-beta2 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Atheme