Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-6598

Опубликовано: 04 янв. 2008
Источник: debian

Описание

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dovecotfixed1:1.0.10-1package
dovecotnot-affectedsargepackage
dovecotno-dsaetchpackage

Примечания

  • http://dovecot.org/list/dovecot-news/2007-December/000057.html

  • low, because issue is only with quite rare configurations

Связанные уязвимости

ubuntu
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

redhat
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

nvd
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

github
больше 3 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

oracle-oval
больше 17 лет назад

ELSA-2008-0297: dovecot security and bug fix update (LOW)