|
|
| |
|
| |
dbmail: authentication bypass
| Package(s): | dbmail |
CVE #(s): | CVE-2007-6714
|
| Created: | April 21, 2008 |
Updated: | May 21, 2008 |
| Description: |
From the Gentoo advisory:
A vulnerability in DBMail's authldap module when used in conjunction
with an Active Directory server has been reported by vugluskr. When
passing a zero length password to the module, it tries to bind
anonymously to the LDAP server. If the LDAP server allows anonymous
binds, this bind succeeds and results in a successful authentication to
DBMail.
By passing an empty password string to the server, an attacker could be
able to log in to any account.
|
| Alerts: |
|
( Log in to post comments)
|
|
|