CVE-2020-3811
published 2020-05-26CVE-2020-3811: qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.77%
75.9th percentile
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | netqmail | — | — |
| netqmail | netqmail | — | — |
| netqmail | netqmail | >= 0 < 1.06-6.2~deb10u1build0.16.04.1 | 1.06-6.2~deb10u1build0.16.04.1 |
| netqmail | netqmail | >= 0 < 1.06-6.2~deb10u1build0.18.04.1 | 1.06-6.2~deb10u1build0.18.04.1 |
| netqmail | netqmail | >= 0 < 1.06-6.2~deb10u1build0.20.04.1 | 1.06-6.2~deb10u1build0.20.04.1 |
| netqmail | netqmail | >= 0 < 1.06-6.2~deb10u1build0.14.04.1+esm1 | 1.06-6.2~deb10u1build0.14.04.1+esm1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
netqmail vulnerabilities
vendor_ubuntu·2020-11-05·CVSS 9.8
CVE-2005-1514 [CRITICAL] netqmail vulnerabilities
Title: netqmail vulnerabilities
Summary: netqmail could be made to crash if it received specially crafted
input.
It was discovered that netqmail did not properly handle certain input. Both
remote and local attackers could use this vulnerability to cause netqmail
to crash or execute arbitrary code. (CVE-2005-1513, CVE-2005-1514,
CVE-2005-1515)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this to bypass email
address validation. (CVE-2020-3811)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this vulnerability to
cause netqmail to disclose sensitive information. (CVE-2020-3812)
Instructions: In general, a standard system update will
Ubuntu
netqmail vulnerabilities
vendor_ubuntu·2020-09-29·CVSS 9.8
CVE-2005-1513 [CRITICAL] netqmail vulnerabilities
Title: netqmail vulnerabilities
Summary: netqmail could be made to crash or run programs as any user (except root) if it
received specially crafted network traffic.
It was discovered that netqmail did not properly handle certain input. Both
remote and local attackers could use this vulnerability to cause netqmail
to crash or execute arbitrary code. (CVE-2005-1513, CVE-2005-1514,
CVE-2005-1515)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this to bypass email
address validation. (CVE-2020-3811)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this vulnerability to
cause netqmail to disclose sensitive information. (CVE-2020-3812)
Ins
GHSA
GHSA-w7qp-9896-2fvp: qmail-verify as used in netqmail 1
ghsa_unreviewed·2022-05-24
CVE-2020-3811 [HIGH] CWE-20 GHSA-w7qp-9896-2fvp: qmail-verify as used in netqmail 1
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
OSV
netqmail vulnerabilities
osv·2020-09-29·CVSS 9.8
CVE-2005-1513 [CRITICAL] netqmail vulnerabilities
netqmail vulnerabilities
It was discovered that netqmail did not properly handle certain input. Both
remote and local attackers could use this vulnerability to cause netqmail
to crash or execute arbitrary code. (CVE-2005-1513, CVE-2005-1514,
CVE-2005-1515)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this to bypass email
address validation. (CVE-2020-3811)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this vulnerability to
cause netqmail to disclose sensitive information. (CVE-2020-3812)
OSV
CVE-2020-3811: qmail-verify as used in netqmail 1
osv·2020-05-26·CVSS 7.5
CVE-2020-3811 [HIGH] CVE-2020-3811: qmail-verify as used in netqmail 1
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/961060https://lists.debian.org/debian-lts-announce/2020/06/msg00002.htmlhttps://usn.ubuntu.com/4556-1/https://www.debian.org/security/2020/dsa-4692https://www.openwall.com/lists/oss-security/2020/05/19/8https://bugs.debian.org/961060https://lists.debian.org/debian-lts-announce/2020/06/msg00002.htmlhttps://usn.ubuntu.com/4556-1/https://www.debian.org/security/2020/dsa-4692https://www.openwall.com/lists/oss-security/2020/05/19/8
2020-05-26
Published