CVE-2001-0990
Summary
| CVE | CVE-2001-0990 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2001-09-04 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Inter7 | Vpopmail | 3.4.1 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.10 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.11 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.11e | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.2 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.3 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.4 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.5 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.6 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.7 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.8 | All | All | All |
| Application | Inter7 | Vpopmail | 3.4.9 | All | All | All |
| Application | Inter7 | Vpopmail | 4.5 | All | All | All |
| Application | Inter7 | Vpopmail | 4.6 | All | All | All |
| Application | Inter7 | Vpopmail | 4.7 | All | All | All |
| Application | Inter7 | Vpopmail | 4.8 | All | All | All |
| Application | Inter7 | Vpopmail | 4.9 | All | All | All |
| Application | Inter7 | Vpopmail | 4.9.10 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityFocus HOME Mailing List: BugTraq | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Inter7 vpopmail MySQL Authentication Data Recovery Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| Page not found | Inter7 Internet Technologies, Inc. | af854a3a-2127-422b-91ae-364da2661108 | www.inter7.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.