CVE
- Id
- 241
- CVE No.
- CVE-1999-0242
- Status
- Candidate
- Description
- Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.
- Phase
- Modified (20000106-01)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Northcutt, Shostack, Wall | REVIEWING(1) Levy
- Comments
- Frech> Ambiguous description: need more detail. Possibly: | XF:linux-pop3d (mktemp() leads to reading e-mail) | Christey> At first glance this might look like CVE-1999-0123 or | CVE-1999-0125, however this particular candidate arises out | of a brief mention of the problem in a larger posting which | discusses CVE-1999-0123 (which may be the same bug as | CVE-1999-0125). See the following phrase in the Bugtraq | post: "one such example of this is in.pop3d" | | However, the original source of this candidate"s description | explicitly mentions shadowed passwords, though it has no | references to help out here.