Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/68028 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2014/06/17/16 | mailing list third party advisory patch |