Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fr2x-9vgp-crvv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

EPSS

Процентиль: 77%
0.01006
Низкий

8.1 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 9 лет назад

The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

CVSS3: 8.1
nvd
больше 9 лет назад

The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

CVSS3: 8.1
debian
больше 9 лет назад

The m_authenticate function in modules/m_sasl.c in Charybdis before 3. ...

EPSS

Процентиль: 77%
0.01006
Низкий

8.1 High

CVSS3

Дефекты

CWE-285