CVE-2012-1576

The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attackers to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
athemeatheme
6.0.0
athemeatheme
6.0.1
athemeatheme
6.0.2
athemeatheme
6.0.3
athemeatheme
6.0.4
athemeatheme
6.0.5
athemeatheme
6.0.6
athemeatheme
6.0.7
athemeatheme
6.0.8
athemeatheme
6.0.9
athemeatheme
7.0.0
athemeatheme
7.0.0:alpha1
athemeatheme
7.0.0:beta1
athemeatheme
7.0.0:beta2
athemeatheme
5.2.0
athemeatheme
5.2.1
athemeatheme
5.2.2
athemeatheme
5.2.3
athemeatheme
5.2.4
athemeatheme
5.2.5
athemeatheme
5.2.6
athemeatheme
5.2.7
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
atheme-services
saucy
not-affected
raring
not-affected
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
ignored
hardy
ignored
Common Weakness Enumeration