Pedro Lineu Orso chetcpasswd 2.3.3 provides a different error message when a request with a valid username fails, compared to a request with an invalid username, which allows remote attackers to determine valid usernames on the system.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chetcpasswd | Chetcpasswd_project | 2.3.3 (including) | 2.3.3 (including) |