CVE-2000-0716: Low severity alt-n mdaemon vulnerability
WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user's email.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0716?
CVE-2000-0716 is considered a moderate security vulnerability due to its potential to allow session hijacking.
How do I fix CVE-2000-0716?
To fix CVE-2000-0716, upgrade to a newer version of MDaemon that addresses this vulnerability.
What are the potential impacts of CVE-2000-0716?
The main impact of CVE-2000-0716 is that it could allow unauthorized access to a user's email by hijacking the session ID.
Which software versions are affected by CVE-2000-0716?
CVE-2000-0716 specifically affects Alt-N MDaemon version 2.8.
Is there a workaround for CVE-2000-0716?
While upgrading is the best solution, a temporary workaround could involve limiting external access to the web client until an upgrade is completed.