Red Hat PAM qpopper User Enumeration Vulnerability
BID:3242
Info
Red Hat PAM qpopper User Enumeration Vulnerability
| Bugtraq ID: | 3242 |
| Class: | Environment Error |
| CVE: |
CVE-2001-1068 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered by Charles Chear <[email protected]>. |
| Vulnerable: |
Qualcomm qpopper 4.0.1 |
| Not Vulnerable: | |
Discussion
Red Hat PAM qpopper User Enumeration Vulnerability
Qpopper is a widely used POP daemon for Unix systems.
When qpopper is used in conjunction with PAM on Red Hat systems, remote attackers can enumerate valid account usernames. This is due to different error messages being output when authentication attempts are made using valid and invalid usernames.
This information may make a brute force attack significantly more feasible.
Note: This vulnerability only affects qpopper when it is used with PAM. Red Hat systems are reported to be vulnerable.
Qpopper is a widely used POP daemon for Unix systems.
When qpopper is used in conjunction with PAM on Red Hat systems, remote attackers can enumerate valid account usernames. This is due to different error messages being output when authentication attempts are made using valid and invalid usernames.
This information may make a brute force attack significantly more feasible.
Note: This vulnerability only affects qpopper when it is used with PAM. Red Hat systems are reported to be vulnerable.
Solution / Fix
Red Hat PAM qpopper User Enumeration Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Qualcomm qpopper 4.0.1
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Qualcomm qpopper 4.0.1
-
Ron Bradburn
Unofficial Patch
http://www.securityfocus.com/data/vulnerabilites/patches/qpopper_enum_ fix.patch
References
Red Hat PAM qpopper User Enumeration Vulnerability
References:
References:
- Qpopper Homepage (Qualcomm)
- Updates, Fixes, and Errata Page (RedHat)