The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Solaris | — | Upgrade consolidation/desktop/desktop-incorporation to version 0.5.11-0.175.3.0.0.28.0 on Solaris 11.3Upgrade library/c++/net6 to version 1.3.14-0.175.2.11.0.3.0 on Solaris 11.2 | May 29, 2017 | Feb 10, 2014 |
| Suse | — | Upgrade net6-debugsourceUpgrade net6Upgrade net6-langUpgrade net6-develUpgrade net6-debuginfo | Dec 12, 2013 | Dec 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub