CVE-2011-4091: Medium severity opensuse vulnerability
The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.
Other sources
Vasiliy Kulikov reported [1] that libnet6 would check for user color collisions prior to authentication. This could allow for the disclosure of certain user information by users that were not authenticated.
This has been corrected in git [2].
[1] http://www.openwall.com/lists/oss-security/2011/10/30/3 [2] http://git.0x539.de/?p=net6.git;a=commitdiff;h=84afca022f063f89bfcd4bb32b1ee911f555abf1;hp=ac61d7fb42a1f977fb527e024bede319c4a9e169
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4091?
CVE-2011-4091 is classified as a medium severity vulnerability due to its impact on user data privacy.
How do I fix CVE-2011-4091?
To mitigate CVE-2011-4091, upgrade libnet6 to version 1.3.14 or later.
What kind of information can be exposed due to CVE-2011-4091?
CVE-2011-4091 allows attackers to access sensitive user information such as usage patterns and color preferences.
Which software versions are affected by CVE-2011-4091?
Affected versions include libnet6 before 1.3.14 and specific distributions like openSUSE 11.3 and 11.4.
Is user authentication bypassed in CVE-2011-4091?
Yes, CVE-2011-4091 involves a lack of authentication before checking user data, leading to unauthorized information access.