CVE-2020-3812
26.05.2020, 13:15
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.Enginsight
Vendor | Product | Version |
---|---|---|
netqmail | netqmail | 1.06 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
canonical | ubuntu_linux | 20.04 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References