cmd5checkpw Qmail Remote Password...

- AV AC AU C I A
发布: 2000-10-16
修订: 2025-04-13

The authentication program cmd5checkpw can function as a plugin to qmail-smtpd-auth, a patch for qmail which supports the SMTP AUTH protocol. Due to improper input validation and error trapping, supplying cmd5checkpw with a non-existent username will cause it to segfault. In turn, the qmail-smtpd-auth qmail patch incorrectly interprets this failure as a successful authentication. As a result, an attacker providing invalid input to cmd5checkpw can create a falsely-authenticated session, leaving the victim host open to receiving and forwarding mail from unauthenticated systems.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息