Username Disclosure in qpopper 4.01 on Red Hat Systems
CVE-2001-1068

Currently unrated

Key Information:

Vendor
Qualcomm
Status
Vendor
CVE Published:
31 August 2001

Summary

The qpopper email server version 4.01, when configured with PAM-based authentication on Red Hat systems, is susceptible to a vulnerability that allows attackers to discern valid usernames. This occurs due to the server's inconsistent error messaging; while providing an invalid username results in a generic error, a valid username yields a specific error indicating the username exists. This discrepancy enables potential attackers to enumerate valid usernames, increasing the risk of targeted attacks against affected systems.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.