CVE-2012-1576: Medium severity Atheme Atheme vulnerability
The myuserdelete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attackers to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1576?
CVE-2012-1576 has a severity rating that suggests it could be exploited to access another user account or cause denial of service.
How do I fix CVE-2012-1576?
To fix CVE-2012-1576, upgrade to Atheme version 5.2.7, 6.0.10, or 7.0.0-beta2 or later.
What versions of Atheme are affected by CVE-2012-1576?
CVE-2012-1576 affects Atheme versions prior to 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2.
Can CVE-2012-1576 cause denial of service?
Yes, CVE-2012-1576 can potentially cause denial of service due to improper cleanup of user data.
What consequences can arise from CVE-2012-1576?
CVE-2012-1576 can allow remote attackers to access sensitive information or disrupt service by compromising user accounts.