Username Disclosure in qpopper 4.01 on Red Hat Systems
CVE-2001-1068
Currently unrated
Summary
The qpopper email server version 4.01, when configured with PAM-based authentication on Red Hat systems, is susceptible to a vulnerability that allows attackers to discern valid usernames. This occurs due to the server's inconsistent error messaging; while providing an invalid username results in a generic error, a valid username yields a specific error indicating the username exists. This discrepancy enables potential attackers to enumerate valid usernames, increasing the risk of targeted attacks against affected systems.
References
Timeline
Vulnerability Reserved
Vulnerability published