Intelligence Center » Browse All Vulnerabilities » CVE-2012-1576
Overview |
|
Vulnerability Score | ![]() |
CVE Id | CVE-2012-1576 |
Last Modified | 04 Apr 2013 11:09:33 |
Published | 01 Oct 2012 04:55:03 |
Confidentiality Impact | ![]() |
Integrity Impact | ![]() |
Availability Impact | ![]() |
Access Vector | NETWORK |
Access Complexity | MEDIUM |
Authentication | SINGLE_INSTANCE |

CVE-2012-1576
Summary
The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attackers to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.
Vulnerable Systems
Application
Atheme 5.2.0
Atheme 5.2.1
Atheme 5.2.2
Atheme 5.2.3
Atheme 5.2.4
Atheme 5.2.5
Atheme 5.2.6
Atheme 5.2.7
Atheme 6.0.0
Atheme 6.0.1
Atheme 6.0.2
Atheme 6.0.3
Atheme 6.0.4
Atheme 6.0.5
Atheme 6.0.6
Atheme 6.0.7
Atheme 6.0.8
Atheme 6.0.9
Atheme 7.0.0
References
BID - 52675
SECUNIA - 48481
CONFIRM - http://jira.atheme.org/browse/SRV-166
CONFIRM - http://git.atheme.org/atheme/commit/?id=3d9551761db2
SECUNIA - 50704
GENTOO - GLSA-201209-09
Last Updated: 27 May 2016 10:56:37