6.8

CVE-2007-6714

DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DbmailDbmail Version2.2.6
DbmailDbmail Version2.2.6 Updaterc1
DbmailDbmail Version2.2.7
DbmailDbmail Version2.2.7 Updaterc1
DbmailDbmail Version2.2.7 Updaterc2
DbmailDbmail Version2.2.7 Updaterc3
DbmailDbmail Version2.2.7 Updaterc4
DbmailDbmail Version2.2.8
DbmailDbmail Version2.2.8 Updaterc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.39% 0.818
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://dbmail.org/index.php?page=news&id=44
Patch
http://osvdb.org/44561
http://secunia.com/advisories/29903
http://secunia.com/advisories/29937
http://secunia.com/advisories/29984
http://www.gentoo.org/security/en/glsa/glsa-200804-24.xml
http://www.mail-archive.com/dbmail-dev%40dbmail.org/msg09942.html
http://www.securityfocus.com/bid/28849
http://www.securitytracker.com/id?1019914
http://www.vupen.com/english/advisories/2008/1321/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/41907
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00549.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00585.html