CVE-2007-6598

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-01-04 02:46

Updated : 2023-12-10 10:40


NVD link : CVE-2007-6598

Mitre link : CVE-2007-6598

CVE.ORG link : CVE-2007-6598


JSON object : View

Products Affected

dovecot

  • dovecot
CWE
CWE-264

Permissions, Privileges, and Access Controls