6.8
CVSSv2

CVE-2007-6598

Published: 04/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Dovecot prior to 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot

Vendor Advisories

It was discovered that in very rare configurations using LDAP, Dovecot may reuse cached connections for users with the same password As a result, a user may be able to login as another if the connection is reused The default Ubuntu configuration of Dovecot was not vulnerable ...
It was discovered that Dovecot, a POP3 and IMAP server, only when used with LDAP authentication and base contains variables, could allow a user to log in to the account of another user with the same password The old stable distribution (sarge) is not affected For the stable distribution (etch), this problem has been fixed in version 10rc15- ...