5

CVE-2006-6682

Pedro Lineu Orso chetcpasswd 2.3.3 provides a different error message when a request with a valid username fails, compared to a request with an invalid username, which allows remote attackers to determine valid usernames on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Chetcpasswd ProjectChetcpasswd Version2.3.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.88% 0.767
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=394454
Third Party Advisory
http://marc.info/?l=bugtraq&m=116371297325564&w=2
Mailing List
http://secunia.com/advisories/22967
Third Party Advisory
Permissions Required
http://www.securityfocus.com/bid/21102
Third Party Advisory
VDB Entry
http://www.osvdb.org/30545
Third Party Advisory
Broken Link
Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/30454
VDB Entry