The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
References
Configurations
History
No history.
Information
Published : 2016-09-21 14:25
Updated : 2025-04-12 10:46
NVD link : CVE-2016-7143
Mitre link : CVE-2016-7143
CVE.ORG link : CVE-2016-7143
JSON object : View
Products Affected
debian
- debian_linux
charybdis_project
- charybdis
CWE
CWE-285
Improper Authorization