6
CVSSv2

CVE-2012-1576

Published: 01/10/2012 Updated: 05/04/2013
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The myuser_delete function in libathemecore/account.c in Atheme 5.x prior to 5.2.7, 6.x prior to 6.0.10, and 7.x prior to 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote malicious users to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.

Vulnerable Product Search on Vulmon Subscribe to Product

atheme atheme 6.0.0

atheme atheme 6.0.1

atheme atheme 6.0.8

atheme atheme 6.0.9

atheme atheme 6.0.4

atheme atheme 6.0.5

atheme atheme 6.0.6

atheme atheme 6.0.7

atheme atheme 6.0.2

atheme atheme 6.0.3

atheme atheme 7.0.0

atheme atheme 5.2.0

atheme atheme 5.2.1

atheme atheme 5.2.5

atheme atheme 5.2.6

atheme atheme 5.2.7

atheme atheme 5.2.2

atheme atheme 5.2.3

atheme atheme 5.2.4