Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2008-0297

Опубликовано: 30 мая 2008
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2008-0297: dovecot security and bug fix update (LOW)

[1.0.7-2]

  • LDAP+auth cache user login mixup (CVE-2007-6598, #427575)
  • insecure mail_extra_groups option (CVE-2008-1199, #436927)

[1.0.7-1]

  • update to latest upstream, fixes a few bugs (#331441, #245249), plus two security vulnerabilities (CVE-2007-2231, CVE-2007-4211)
  • increased default login_process_size to 64 (#253363)

Связанные уязвимости

ubuntu
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

redhat
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

nvd
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

debian
больше 17 лет назад

Dovecot before 1.0.10, with certain configuration options including us ...

github
около 3 лет назад

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.