Software: Alt-N MDaemon v13.0.3 and prior versions Vendor: http://www.altn.com/ Vulnerability Type: Username Enumeration Remote: Yes Local: No Discovered: 14 September 2012 Reported: 19 December 2012 Disclosed: 18 February 2013 Whitepaper:Pwning_MDaemon.pdf
Alt-N WorldClient is prone to a username-enumeration weakness by querying the user's Free-Busy schedule. The DTSTART and DTEND parameters in the returned FBData.vfb file, may indicate whether an email address/username is valid or not.
Attackers may exploit this weakness to discern valid usernames. This may aid them in brute-force password cracking or other attacks.
Alt-N MDaemon v13.0.3 & v12.5.6 were tested and found vulnerable; other versions may also be affected.