CVE-2020-3812
published 2020-05-26CVE-2020-3812: qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.43%
35.0th percentile
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | netqmail | — | — |
| netqmail | netqmail | — | — |
| netqmail | netqmail | >= 0 < 1.06-6.2~deb10u1build0.16.04.1 | 1.06-6.2~deb10u1build0.16.04.1 |
| netqmail | netqmail | >= 0 < 1.06-6.2~deb10u1build0.18.04.1 | 1.06-6.2~deb10u1build0.18.04.1 |
| netqmail | netqmail | >= 0 < 1.06-6.2~deb10u1build0.20.04.1 | 1.06-6.2~deb10u1build0.20.04.1 |
| netqmail | netqmail | >= 0 < 1.06-6.2~deb10u1build0.14.04.1+esm1 | 1.06-6.2~deb10u1build0.14.04.1+esm1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
netqmail vulnerabilities
vendor_ubuntu·2020-11-05·CVSS 9.8
CVE-2005-1514 [CRITICAL] netqmail vulnerabilities
Title: netqmail vulnerabilities
Summary: netqmail could be made to crash if it received specially crafted
input.
It was discovered that netqmail did not properly handle certain input. Both
remote and local attackers could use this vulnerability to cause netqmail
to crash or execute arbitrary code. (CVE-2005-1513, CVE-2005-1514,
CVE-2005-1515)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this to bypass email
address validation. (CVE-2020-3811)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this vulnerability to
cause netqmail to disclose sensitive information. (CVE-2020-3812)
Instructions: In general, a standard system update will
Ubuntu
netqmail vulnerabilities
vendor_ubuntu·2020-09-29·CVSS 9.8
CVE-2005-1513 [CRITICAL] netqmail vulnerabilities
Title: netqmail vulnerabilities
Summary: netqmail could be made to crash or run programs as any user (except root) if it
received specially crafted network traffic.
It was discovered that netqmail did not properly handle certain input. Both
remote and local attackers could use this vulnerability to cause netqmail
to crash or execute arbitrary code. (CVE-2005-1513, CVE-2005-1514,
CVE-2005-1515)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this to bypass email
address validation. (CVE-2020-3811)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this vulnerability to
cause netqmail to disclose sensitive information. (CVE-2020-3812)
Ins
GHSA
GHSA-w98m-2722-xcvc: qmail-verify as used in netqmail 1
ghsa_unreviewed·2022-05-24
CVE-2020-3812 [LOW] CWE-200 GHSA-w98m-2722-xcvc: qmail-verify as used in netqmail 1
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.
OSV
netqmail vulnerabilities
osv·2020-09-29·CVSS 9.8
CVE-2005-1513 [CRITICAL] netqmail vulnerabilities
netqmail vulnerabilities
It was discovered that netqmail did not properly handle certain input. Both
remote and local attackers could use this vulnerability to cause netqmail
to crash or execute arbitrary code. (CVE-2005-1513, CVE-2005-1514,
CVE-2005-1515)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this to bypass email
address validation. (CVE-2020-3811)
It was discovered that netqmail did not properly handle certain input when
validating email addresses. An attacker could use this vulnerability to
cause netqmail to disclose sensitive information. (CVE-2020-3812)
OSV
CVE-2020-3812: qmail-verify as used in netqmail 1
osv·2020-05-26·CVSS 5.5
CVE-2020-3812 [MEDIUM] CVE-2020-3812: qmail-verify as used in netqmail 1
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/961060https://lists.debian.org/debian-lts-announce/2020/06/msg00002.htmlhttps://usn.ubuntu.com/4556-1/https://www.debian.org/security/2020/dsa-4692https://www.openwall.com/lists/oss-security/2020/05/19/8https://bugs.debian.org/961060https://lists.debian.org/debian-lts-announce/2020/06/msg00002.htmlhttps://usn.ubuntu.com/4556-1/https://www.debian.org/security/2020/dsa-4692https://www.openwall.com/lists/oss-security/2020/05/19/8
2020-05-26
Published