CVE
- Id
- 29955
- CVE No.
- CVE-2007-6598
- Status
- Candidate
- Description
- Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
- Phase
- Assigned (20071231)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
316752 | 29955 | CVE-2007-6598 | BUGTRAQ:20080103 Re: rPSA-2008-0001-1 dovecot | View |
316753 | 29955 | CVE-2007-6598 | URL:http://www.securityfocus.com/archive/1/archive/1/485787/100/0/threaded | View |
316754 | 29955 | CVE-2007-6598 | BUGTRAQ:20080103 rPSA-2008-0001-1 dovecot | View |
316755 | 29955 | CVE-2007-6598 | URL:http://www.securityfocus.com/archive/1/archive/1/485779/100/0/threaded | View |
316756 | 29955 | CVE-2007-6598 | MLIST:[Dovecot-news] 20071221 Security hole #4: Specific LDAP + auth cache configuration may mix up user logins | View |
316757 | 29955 | CVE-2007-6598 | URL:http://dovecot.org/list/dovecot-news/2007-December/000057.html | View |
316758 | 29955 | CVE-2007-6598 | MLIST:[Dovecot-news] 20071229 v1.0.10 released | View |
316759 | 29955 | CVE-2007-6598 | URL:http://dovecot.org/list/dovecot-news/2007-December/000058.html | View |
316760 | 29955 | CVE-2007-6598 | CONFIRM:https://issues.rpath.com/browse/RPL-2076 | View |
316761 | 29955 | CVE-2007-6598 | DEBIAN:DSA-1457 | View |
316762 | 29955 | CVE-2007-6598 | URL:http://www.debian.org/security/2008/dsa-1457 | View |
316763 | 29955 | CVE-2007-6598 | REDHAT:RHSA-2008:0297 | View |
316764 | 29955 | CVE-2007-6598 | URL:http://www.redhat.com/support/errata/RHSA-2008-0297.html | View |
316765 | 29955 | CVE-2007-6598 | SUSE:SUSE-SR:2008:020 | View |
316766 | 29955 | CVE-2007-6598 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00004.html | View |
316767 | 29955 | CVE-2007-6598 | UBUNTU:USN-567-1 | View |
316768 | 29955 | CVE-2007-6598 | URL:http://www.ubuntu.com/usn/usn-567-1 | View |
316769 | 29955 | CVE-2007-6598 | BID:27093 | View |
316770 | 29955 | CVE-2007-6598 | URL:http://www.securityfocus.com/bid/27093 | View |
316771 | 29955 | CVE-2007-6598 | OVAL:oval:org.mitre.oval:def:10458 | View |
316772 | 29955 | CVE-2007-6598 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10458 | View |
316773 | 29955 | CVE-2007-6598 | SECUNIA:30342 | View |
316774 | 29955 | CVE-2007-6598 | URL:http://secunia.com/advisories/30342 | View |
316775 | 29955 | CVE-2007-6598 | VUPEN:ADV-2008-0017 | View |
316776 | 29955 | CVE-2007-6598 | URL:http://www.vupen.com/english/advisories/2008/0017 | View |
316777 | 29955 | CVE-2007-6598 | OSVDB:39876 | View |
316778 | 29955 | CVE-2007-6598 | URL:http://osvdb.org/39876 | View |
316779 | 29955 | CVE-2007-6598 | SECUNIA:28227 | View |
316780 | 29955 | CVE-2007-6598 | URL:http://secunia.com/advisories/28227 | View |
316781 | 29955 | CVE-2007-6598 | SECUNIA:28271 | View |
316782 | 29955 | CVE-2007-6598 | URL:http://secunia.com/advisories/28271 | View |
316783 | 29955 | CVE-2007-6598 | SECUNIA:28404 | View |
316784 | 29955 | CVE-2007-6598 | URL:http://secunia.com/advisories/28404 | View |
316785 | 29955 | CVE-2007-6598 | SECUNIA:28434 | View |
316786 | 29955 | CVE-2007-6598 | URL:http://secunia.com/advisories/28434 | View |
316787 | 29955 | CVE-2007-6598 | SECUNIA:32151 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
45694 | JVNDB-2008-001004 | PostgreSQL の index() 関数における権限昇格の脆弱性 | PostgreSQL には、index() 関数内の VACUUM および ANALYZE オペレーションの権限をテーブル所有者の権限ではなく、スーパーユーザ権限を使用する、および index() 関数内に SET ROLE および SET SESSION AUTHORIZATION を定義することが可能な脆弱性が存在します。 | CVE-2007-6600 | 29955 | 5.5 | http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001004.html | View |