ZPop3D Bad Login Logging Failure Vulnerability
BID:3990
Info
ZPop3D Bad Login Logging Failure Vulnerability
| Bugtraq ID: | 3990 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2002 12:00AM |
| Updated: | Jan 30 2002 12:00AM |
| Credit: | This vulnerability was announced by the author in a Freshmeat update on January 23, 2002. |
| Vulnerable: |
zpop3d zpop3d 0.6 .0 |
| Not Vulnerable: |
zpop3d zpop3d 0.6.1 zpop3d zpop3d 0.5.6 |
Discussion
ZPop3D Bad Login Logging Failure Vulnerability
zpop3d is a freely available, open source Post Office Protocol 3 Daemon. It is available for the Unix and Linux Operating Systems.
zpop3d does not provide sufficient logging facilities. When a user attempts to log into a zpop3d server and does not provide sufficient credentials, the attempt is not logged.
This could allow a remote user to launch a brute force crack attack using various username and password combinations without being detected by system logging facilities.
zpop3d is a freely available, open source Post Office Protocol 3 Daemon. It is available for the Unix and Linux Operating Systems.
zpop3d does not provide sufficient logging facilities. When a user attempts to log into a zpop3d server and does not provide sufficient credentials, the attempt is not logged.
This could allow a remote user to launch a brute force crack attack using various username and password combinations without being detected by system logging facilities.
Exploit / POC
ZPop3D Bad Login Logging Failure Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
ZPop3D Bad Login Logging Failure Vulnerability
Solution:
A fixed version is available:
zpop3d zpop3d 0.6 .0
Solution:
A fixed version is available:
zpop3d zpop3d 0.6 .0
-
Lauent Monin zpop3d_0.6.1.tar.bz2
http://www.norz.org/software/zpop3d_0.6.1.tar.bz2