Executive brief
A vulnerability in certain legacy Linux systems allows remote attackers to bypass security controls and access user email files. This occurs on systems using shadow passwords when communicating via the POP3 mail protocol. An exploit could lead to the unauthorized reading of sensitive communications and potential data theft.
Technical details
This vulnerability involves an authentication or access control bypass in the POP3 service on legacy Linux distributions. When shadow passwords are implemented, the POP3 daemon may fail to properly validate credentials or restrict access to mail spools. A remote, unauthenticated attacker can exploit this flaw over the network to read or manipulate mail files. The issue is specific to the interaction between the POP3 service and the shadow password suite on affected systems. Information regarding specific patched versions is limited due to the age of the advisory.
Affected products
- Linux Linux Legacy versions using shadow passwords and POP3
Timeline
- 1995-03-01: disclosed: Initial publication date reported by NVD.