J-Security Center

Title: ZPop3D Bad Login Logging Failure Vulnerability

Severity: MODERATE

Description:

zpop3d is a freely available, open source Post Office Protocol 3 Daemon. It is available for the Unix and Linux Operating Systems.

A problem with zpop3d could make it possible for a remote user to launch an undetected brute force attack against the daemon. The problem is in the logging functions of the program.

zpop3d does not provide sufficient logging facilities. When a user attempts to log into a zpop3d server and does not provide sufficient credentials, the attempt is not logged.

This could allow a remote user to launch a brute force crack attack using various username and password combinations without being detected by system logging facilities.

Affected Products:

  • zpop3d zpop3d 0.6.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.