PT-2016-7234 · Charybdis · Charybdis

Antoine Beaupré

·

Published

2016-09-06

·

Updated

2024-06-15

·

CVE-2016-7143

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Charybdis versions prior to 3.5.3
Description The issue allows remote attackers to spoof certificate fingerprints, enabling them to log in as another user. This is achieved by crafting the AUTHENTICATE parameter. The m authenticate function in modules/m sasl.c is specifically vulnerable to this type of attack.
Recommendations For versions prior to 3.5.3, update to version 3.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the m authenticate function until a patch is applied. Avoid using the crafted AUTHENTICATE parameter in the affected module until the issue is resolved.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-7143
DSA-3661-1
OPENSUSE-SU-2024:10220-1
OPENSUSE-SU-2024:11392-1

Affected Products

Charybdis