Vulnerability Name: | CVE-2005-0198 (CCN-19120) | ||||||||||||||||
Assigned: | 2005-01-27 | ||||||||||||||||
Published: | 2005-01-27 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CCN Type: University of Washington FTP site imap/ Source: MITRE Type: CNA CVE-2005-0198 Source: CCN Type: RHSA-2005-128 imap security update Source: CCN Type: SA14057 UW-imapd CRAM-MD5 Authentication Bypass Vulnerability Source: SECUNIA Type: UNKNOWN 14057 Source: SECUNIA Type: UNKNOWN 14097 Source: CCN Type: SECTRACK ID: 1013037 UW IMAP CRAM-MD5 Authentication Flaw Lets Remote Users Access Arbitrary IMAP Accounts Source: SECTRACK Type: UNKNOWN 1013037 Source: CCN Type: GLSA-200502-02 UW IMAP: CRAM-MD5 authentication bypass Source: GENTOO Type: Patch GLSA-200502-02 Source: CCN Type: US-CERT VU#702777 UW-imapd fails to properly authenticate users when using CRAM-MD5 Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#702777 Source: CONFIRM Type: Patch, US Government Resource http://www.kb.cert.org/vuls/id/CRDY-68QSL5 Source: MANDRAKE Type: UNKNOWN MDKSA-2005:026 Source: REDHAT Type: Patch, Vendor Advisory RHSA-2005:128 Source: BID Type: UNKNOWN 12391 Source: CCN Type: BID-12391 University Of Washington IMAP Server CRAM-MD5 Remote Authentication Bypass Vulnerability Source: CCN Type: TLSA-2005-32 CRAM-MD5 vulnerability discovered in IMAP Source: XF Type: UNKNOWN wuimapd-crammd5-gain-access(19120) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11306 Source: SUSE Type: SUSE-SA:2005:012 imap: remote authentication bypass Source: SUSE Type: SUSE-SR:2005:006 SUSE Security Summary Report | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |