ISOMAN

CVE

CVE-2020-3812

qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.

Severity
MEDIUM
CVSS
5.5
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu20.04.6 amd64 desktopunknownsource
Ubuntu20.04.6 amd64 live-serverunknownsource

References

  1. https://bugs.debian.org/961060
  2. https://lists.debian.org/debian-lts-announce/2020/06/msg00002.html
  3. https://usn.ubuntu.com/4556-1/
  4. https://www.debian.org/security/2020/dsa-4692
  5. https://www.openwall.com/lists/oss-security/2020/05/19/8
  6. https://bugs.debian.org/961060
  7. https://lists.debian.org/debian-lts-announce/2020/06/msg00002.html
  8. https://usn.ubuntu.com/4556-1/
  9. https://www.debian.org/security/2020/dsa-4692
  10. https://www.openwall.com/lists/oss-security/2020/05/19/8