CVE Vulnerabilities

CVE-2001-0990

Published: Sep 04, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.

Affected Software

NameVendorStart VersionEnd Version
VpopmailInter73.4.1 (including)3.4.1 (including)
VpopmailInter73.4.2 (including)3.4.2 (including)
VpopmailInter73.4.3 (including)3.4.3 (including)
VpopmailInter73.4.4 (including)3.4.4 (including)
VpopmailInter73.4.5 (including)3.4.5 (including)
VpopmailInter73.4.6 (including)3.4.6 (including)
VpopmailInter73.4.7 (including)3.4.7 (including)
VpopmailInter73.4.8 (including)3.4.8 (including)
VpopmailInter73.4.9 (including)3.4.9 (including)
VpopmailInter73.4.10 (including)3.4.10 (including)
VpopmailInter73.4.11 (including)3.4.11 (including)
VpopmailInter73.4.11e (including)3.4.11e (including)
VpopmailInter74.5 (including)4.5 (including)
VpopmailInter74.6 (including)4.6 (including)
VpopmailInter74.7 (including)4.7 (including)
VpopmailInter74.8 (including)4.8 (including)
VpopmailInter74.9 (including)4.9 (including)
VpopmailInter74.9.10 (including)4.9.10 (including)

References