Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-0599

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2006-0599
Last Modified 05 Sep 2008 04:59:43
Published 13 Feb 2006 06:06:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-0599

Summary

The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.

Vulnerable Systems

Application

  • Stefan Ritt Elog Web Logbook 2.0.0

  • Stefan Ritt Elog Web Logbook 2.0.1

  • Stefan Ritt Elog Web Logbook 2.0.2

  • Stefan Ritt Elog Web Logbook 2.0.3

  • Stefan Ritt Elog Web Logbook 2.0.4

  • Stefan Ritt Elog Web Logbook 2.0.5

  • Stefan Ritt Elog Web Logbook 2.1.0

  • Stefan Ritt Elog Web Logbook 2.1.1

  • Stefan Ritt Elog Web Logbook 2.1.2

  • Stefan Ritt Elog Web Logbook 2.1.3

  • Stefan Ritt Elog Web Logbook 2.2.0

  • Stefan Ritt Elog Web Logbook 2.2.1

  • Stefan Ritt Elog Web Logbook 2.2.2

  • Stefan Ritt Elog Web Logbook 2.2.3

  • Stefan Ritt Elog Web Logbook 2.2.4

  • Stefan Ritt Elog Web Logbook 2.4

  • Stefan Ritt Elog Web Logbook 2.5

  • Stefan Ritt Elog Web Logbook 2.5.6


References

DEBIAN - DSA-967

SECUNIA - 18783

BID - 16579

MISC - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528

MISC - http://bugs.debian.org/cgi-bin/bugreport.cgi/0003-r1472-Do-not-distinguish-between-invalid-user-name-and-invalid-password.txt?bug=349528;msg=15;att=3

XF - elog-elog-elogd-user-enumeration(24706)


Last Updated: 27 May 2016 10:41:43