First published: Tue Sep 04 2001(Updated: )
Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Inter7 Vpopmail | =3.4.1 | |
Inter7 Vpopmail | =3.4.2 | |
Inter7 Vpopmail | =3.4.3 | |
Inter7 Vpopmail | =3.4.4 | |
Inter7 Vpopmail | =3.4.5 | |
Inter7 Vpopmail | =3.4.6 | |
Inter7 Vpopmail | =3.4.7 | |
Inter7 Vpopmail | =3.4.8 | |
Inter7 Vpopmail | =3.4.9 | |
Inter7 Vpopmail | =3.4.10 | |
Inter7 Vpopmail | =3.4.11 | |
Inter7 Vpopmail | =3.4.11e | |
Inter7 Vpopmail | =4.5 | |
Inter7 Vpopmail | =4.6 | |
Inter7 Vpopmail | =4.7 | |
Inter7 Vpopmail | =4.8 | |
Inter7 Vpopmail | =4.9 | |
Inter7 Vpopmail | =4.9.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0990 is classified as a moderate severity vulnerability.
To fix CVE-2001-0990, upgrade to vpopmail version 4.10.36 or later.
CVE-2001-0990 exposes MySQL usernames and passwords compiled in cleartext.
Versions 4.10.35 and earlier, as well as several 3.x versions of Inter7 vpopmail, are affected by CVE-2001-0990.
Yes, local users can exploit CVE-2001-0990 by inspecting the vpopmail programs using the libvpopmail.a library.