Qpopper Authentication Timing Response Account Enumeration

medium Nessus Plugin ID 12279

Synopsis

The remote mail server is affected by an account enumeration vulnerability.

Description

The remote server appears to be running a version of Qpopper that is older than 4.0.6.

Versions older than 4.0.6 are vulnerable to a bug where remote attackers can enumerate valid usernames based on server responses during the authentication process.

Solution

There is no known solution at this time.

Plugin Details

Severity: Medium

ID: 12279

File Name: qpopper_user_disclosure.nasl

Version: 1.19

Type: remote

Family: Misc.

Published: 6/16/2004

Updated: 8/8/2018

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Exploit Available: true

Exploit Ease: No exploit is required

Vulnerability Publication Date: 6/18/2003

Reference Information

BID: 7110