5
CVSSv2

CVE-2013-4223

Published: 23/05/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Gentoo Nullmailer package prior to 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file.

Vulnerable Product Search on Vulmon Subscribe to Product

gentoo nullmailer 1.11

Vendor Advisories

Debian Bug report logs - #684619 [nullmailer] Debconf prompts for info that might contain password, saves to world-readable file (CVE-2013-4223) Package: nullmailer; Maintainer for nullmailer is David Bremner <bremner@debianorg>; Source for nullmailer is src:nullmailer (PTS, buildd, popcon) Reported by: Aaron Schrab <aar ...