|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Qpopper contains a flaw that may allow a malicious user to get unauthorized information. The issue is due to different error messages being output when authentication attempts are made using valid and invalid usernames. When qpopper is used in conjunction with PAM, remote attackers can enumerate valid account usernames, resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Qpopper
 |
4.0.1 |
|
|
|
|
Credit |
- Charles Chear - presto
tpgn.net -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|