7.5
CVSSv2

CVE-2005-0198

Published: 02/05/2005 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote malicious users to authenticate as arbitrary users.

Vulnerable Product Search on Vulmon Subscribe to Product

university of washington uw-imap

Vendor Advisories

Synopsis imap security update Type/Severity Security Advisory: Moderate Topic Updated imap packages to correct a security vulnerability in CRAM-MD5authentication are now available for Red Hat Enterprise Linux 3This update has been rated as having moderate security impact by the RedHat Security Response Tea ...