PT-2016-7234 · Charybdis · Charybdis

Antoine Beaupré

·

Publicado

2016-09-06

·

Atualizado

2024-06-15

·

CVE-2016-7143

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Charybdis versions prior to 3.5.3
Description The issue allows remote attackers to spoof certificate fingerprints, enabling them to log in as another user. This is achieved by crafting the AUTHENTICATE parameter. The m authenticate function in modules/m sasl.c is specifically vulnerable to this type of attack.
Recommendations For versions prior to 3.5.3, update to version 3.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the m authenticate function until a patch is applied. Avoid using the crafted AUTHENTICATE parameter in the affected module until the issue is resolved.

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-7143
DSA-3661-1
OPENSUSE-SU-2024:10220-1
OPENSUSE-SU-2024:11392-1

Produtos afetados

Charybdis