Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-3812

Опубликовано: 26 мая 2020
Источник: debian

Описание

qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
netqmailfixed1.06-6.2package

Примечания

  • https://www.openwall.com/lists/oss-security/2020/05/19/8

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.

CVSS3: 5.5
nvd
больше 5 лет назад

qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.

CVSS3: 5.5
github
больше 3 лет назад

qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.

CVSS3: 5.5
fstec
больше 5 лет назад

Уязвимость модуля qmail-verify почтового клиента netqmail, позволяющая нарушителю получить доступ к конфиденциальным данным