Lucene search

K
cve[email protected]CVE-2011-4091
HistoryFeb 10, 2014 - 6:15 p.m.

CVE-2011-4091

2014-02-1018:15:09
CWE-287
web.nvd.nist.gov
27
cve-2011-4091
libobby server
libnet6
remote attackers
sensitive information
nvd
authentication
server-usage patterns

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

64.9%

The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.

Affected configurations

NVD
Node
opensuseopensuseMatch11.3
OR
opensuseopensuseMatch11.4
Node
oraclesolarisMatch11.2
Node
armin_burgmeiernet6Range1.3.13
OR
armin_burgmeiernet6Match1.3.1
OR
armin_burgmeiernet6Match1.3.2
OR
armin_burgmeiernet6Match1.3.3
OR
armin_burgmeiernet6Match1.3.4
OR
armin_burgmeiernet6Match1.3.5
OR
armin_burgmeiernet6Match1.3.6
OR
armin_burgmeiernet6Match1.3.7
OR
armin_burgmeiernet6Match1.3.8
OR
armin_burgmeiernet6Match1.3.9
OR
armin_burgmeiernet6Match1.3.10
OR
armin_burgmeiernet6Match1.3.11
OR
armin_burgmeiernet6Match1.3.12

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

64.9%