PT-2001-2213 · Red Hat · Qpopper

Published

2001-08-31

·

Updated

2017-12-19

·

CVE-2001-1068

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions qpopper version 4.01
Description The issue allows remote attackers to determine valid usernames on the system by generating different error messages when an invalid username is provided instead of a valid name. This occurs on Red Hat systems with qpopper 4.01 that uses PAM based authentication.
Recommendations For qpopper version 4.01, consider modifying the authentication mechanism to provide uniform error messages for both valid and invalid usernames to prevent attackers from determining valid usernames.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1068

Affected Products

Qpopper