CVE-2011-4091
published 2014-02-10CVE-2011-4091: The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.73%
84.5th percentile
The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| armin_burgmeier | net6 | <= 1.3.13 | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| armin_burgmeier | net6 | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4093 CVE-2011-4091 net6 various flaws [fedora-all]
bugzilla·2011-11-01·CVSS 5.0
CVE-2011-4093 [MEDIUM] CVE-2011-4093 CVE-2011-4091 net6 various flaws [fedora-all]
CVE-2011-4093 CVE-2011-4091 net6 various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=750631
Pl
Bugzilla
CVE-2011-4091 net6: user information exposure flaw
bugzilla·2011-11-01·CVSS 5.0
CVE-2011-4091 [MEDIUM] CVE-2011-4091 net6: user information exposure flaw
CVE-2011-4091 net6: user information exposure flaw
Vasiliy Kulikov reported [1] that libnet6 would check for user color collisions prior to authentication. This could allow for the disclosure of certain user information by users that were not authenticated.
This has been corrected in git [2].
[1] http://www.openwall.com/lists/oss-security/2011/10/30/3
[2] http://git.0x539.de/?p=net6.git;a=commitdiff;h=84afca022f063f89bfcd4bb32b1ee911f555abf1;hp=ac61d7fb42a1f977fb527e024bede319c4a9e169
Discussion:
Created net6 tracking bugs for this issue
Affects: fedora-all [bug 750633]
Affects: epel-all [bug 750634]
---
net6-1.3.14-1.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
---
net6-1.3.14-1.el5 has been pushed
Bugzilla
CVE-2011-4093 CVE-2011-4091 net6 various flaws [epel-all]
bugzilla·2011-11-01·CVSS 5.0
CVE-2011-4093 [MEDIUM] CVE-2011-4093 CVE-2011-4091 net6 various flaws [epel-all]
CVE-2011-4093 CVE-2011-4091 net6 various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=750631
Plea
http://git.0x539.de/?p=net6.git%3Ba=commitdiff%3Bh=84afca022f063f89bfcd4bb32b1ee911f555abf1%3Bhp=ac61d7fb42a1f977fb527e024bede319c4a9e169http://lists.opensuse.org/opensuse-updates/2012-01/msg00044.htmlhttp://lists.opensuse.org/opensuse-updates/2012-01/msg00054.htmlhttp://www.openwall.com/lists/oss-security/2011/10/31/1http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttps://bugzilla.novell.com/show_bug.cgi?id=727708https://bugzilla.redhat.com/show_bug.cgi?id=750632http://git.0x539.de/?p=net6.git%3Ba=commitdiff%3Bh=84afca022f063f89bfcd4bb32b1ee911f555abf1%3Bhp=ac61d7fb42a1f977fb527e024bede319c4a9e169http://lists.opensuse.org/opensuse-updates/2012-01/msg00044.htmlhttp://lists.opensuse.org/opensuse-updates/2012-01/msg00054.htmlhttp://www.openwall.com/lists/oss-security/2011/10/31/1http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttps://bugzilla.novell.com/show_bug.cgi?id=727708https://bugzilla.redhat.com/show_bug.cgi?id=750632
2014-02-10
Published