Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-6598

Опубликовано: 04 янв. 2008
Источник: debian
EPSS Низкий

Описание

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dovecotfixed1:1.0.10-1package
dovecotnot-affectedsargepackage
dovecotno-dsaetchpackage

Примечания

  • http://dovecot.org/list/dovecot-news/2007-December/000057.html

  • low, because issue is only with quite rare configurations

EPSS

Процентиль: 83%
0.02083
Низкий

Связанные уязвимости

ubuntu
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

redhat
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

nvd
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

github
около 3 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

oracle-oval
около 17 лет назад

ELSA-2008-0297: dovecot security and bug fix update (LOW)

EPSS

Процентиль: 83%
0.02083
Низкий