CVE-2020-3812: Medium severity netqmail netqmail vulnerability
Last updated 25 August 2025
Other sources
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2020-3812.
What is the severity of CVE-2020-3812?
The severity of CVE-2020-3812 is medium.
What is the affected software for CVE-2020-3812?
The affected software for CVE-2020-3812 is netqmail 1.06.
How can a local attacker exploit CVE-2020-3812?
A local attacker can exploit CVE-2020-3812 by testing for the existence of files and directories anywhere in the filesystem.
Are there any known references for CVE-2020-3812?
Yes, there are references available for CVE-2020-3812. They can be found at the following links: [reference1](https://bugs.debian.org/961060), [reference2](https://www.debian.org/security/2020/dsa-4692), [reference3](https://www.openwall.com/lists/oss-security/2020/05/19/8).