PT-2020-3627 · Qmail+2 · Netqmail+2

Georgi Guninski

·

Published

2020-05-24

·

Updated

2022-04-28

·

CVE-2020-3812

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions netqmail version 1.06
Description The issue is related to the qmail-verify module in the netqmail email client, which lacks protection for service data. This can allow an attacker to gain access to confidential data. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.
Recommendations For netqmail version 1.06, consider restricting the privileges of the qmail-verify module to prevent it from running as root, or apply configuration changes to limit its access to sensitive files and directories. As a temporary workaround, consider disabling the qmail-verify module until a patch is available.

Exploit

Fix

Improper Privilege Management

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03974
CVE-2020-3812
DLA-2234-1
DSA-4692-1
USN-4556-1
USN-4621-1

Affected Products

Linuxmint
Ubuntu
Netqmail