VYPR
Medium severity5.5NVD Advisory· Published May 26, 2020· Updated Jun 17, 2026

CVE-2020-3812

CVE-2020-3812

Description

qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Range: =1.06
  • Debian/netqmailv5
    Range: 1.06
  • cpe:2.3:a:netqmail:netqmail:1.06:*:*:*:*:*:*:*
  • Debian/linux3 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.