CVE-2012-1576
Published Oct 1, 2012
Last updated 12 years ago
Overview
- Description
- The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attackers to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6
- Impact score
- 6.4
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-264
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atheme:atheme:6.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B1DCABB-A84F-4888-86A2-BABED67211B8" }, { "criteria": "cpe:2.3:a:atheme:atheme:6.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7DEBEF58-D73D-4C0B-A24B-54A4F5A93336" }, { "criteria": "cpe:2.3:a:atheme:atheme:6.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19464281-B5DB-434C-A7FD-468E8A4F540C" }, { "criteria": "cpe:2.3:a:atheme:atheme:6.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB6310D6-8C40-44D6-8627-575F9BC57AC8" }, { "criteria": "cpe:2.3:a:atheme:atheme:6.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7B0F31A-C8A5-417D-B01D-F89F128E8686" }, { "criteria": "cpe:2.3:a:atheme:atheme:6.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA362B76-7AEB-4079-B1C8-62397A36E008" }, { "criteria": "cpe:2.3:a:atheme:atheme:6.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37FDD421-DF70-41B1-AA92-F95360EBC678" }, { "criteria": "cpe:2.3:a:atheme:atheme:6.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CD152CB-A21C-46BA-A762-E9CC27CA6D78" }, { "criteria": "cpe:2.3:a:atheme:atheme:6.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "337B8A9C-57DB-4D63-A1BF-5E5A4A55EB72" }, { "criteria": "cpe:2.3:a:atheme:atheme:6.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8920E9DF-92DC-4751-86EA-041B5CE9D224" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atheme:atheme:7.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9DF86772-5F7B-4A3A-AAB1-CEB2B5AA9707" }, { "criteria": "cpe:2.3:a:atheme:atheme:7.0.0:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "832E0227-0FE2-41D5-AA17-E1A736A2EC83" }, { "criteria": "cpe:2.3:a:atheme:atheme:7.0.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1DA4FA40-675A-4A4A-BE39-8046A94593B0" }, { "criteria": "cpe:2.3:a:atheme:atheme:7.0.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0C82BD1-0566-4E8F-8158-DD38202CB463" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atheme:atheme:5.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20F959F7-52A2-4087-AC9D-1AAB2050D996" }, { "criteria": "cpe:2.3:a:atheme:atheme:5.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F55AC1B1-B9D8-48F4-9813-FC4E0A8CB07B" }, { "criteria": "cpe:2.3:a:atheme:atheme:5.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34BF098C-382B-445A-8F89-FEE04848089B" }, { "criteria": "cpe:2.3:a:atheme:atheme:5.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EEFE7F73-5F9C-4E7C-89D0-11E3CE9CC394" }, { "criteria": "cpe:2.3:a:atheme:atheme:5.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "50954C79-38F5-4382-BBFA-83519AF806E8" }, { "criteria": "cpe:2.3:a:atheme:atheme:5.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0D044B81-EE6C-4A6C-A3F8-1D34AC89FD14" }, { "criteria": "cpe:2.3:a:atheme:atheme:5.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7070831B-55E6-487D-B4A2-33B139E5CBD3" }, { "criteria": "cpe:2.3:a:atheme:atheme:5.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1BD940C-8F47-4A36-BCFC-2AB3CC7AE0E2" } ], "operator": "OR" } ] } ]