Vulnerability Name: | CVE-2008-1218 (CCN-41085) | ||||||||||||||||||||||||
Assigned: | 2008-03-09 | ||||||||||||||||||||||||
Published: | 2008-03-09 | ||||||||||||||||||||||||
Updated: | 2018-10-11 | ||||||||||||||||||||||||
Summary: | Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
6.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-255 | ||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2008-1218 Source: CCN Type: Dovecot Download Web site Secure IMAP server Source: CCN Type: Dovecot Changelog, Sun Mar 9 13:09:44 EET 2008 Security hole #6: Some passdbs allowed users to log in without a valid password Source: SUSE Type: UNKNOWN SUSE-SR:2008:020 Source: SECUNIA Type: UNKNOWN 29226 Source: CCN Type: SA29295 Dovecot Authentication Bypass Vulnerability Source: SECUNIA Type: UNKNOWN 29295 Source: SECUNIA Type: UNKNOWN 29364 Source: SECUNIA Type: UNKNOWN 29385 Source: SECUNIA Type: UNKNOWN 29396 Source: SECUNIA Type: UNKNOWN 29557 Source: SECUNIA Type: UNKNOWN 32151 Source: GENTOO Type: UNKNOWN GLSA-200803-25 Source: MISC Type: UNKNOWN http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0108 Source: DEBIAN Type: UNKNOWN DSA-1516 Source: DEBIAN Type: DSA-1516 dovecot -- privilege escalation Source: MLIST Type: UNKNOWN [Dovecot-news] 20080309 Security hole #6: Some passdbs allowed users to log in without a valid password Source: MLIST Type: UNKNOWN [Dovecot-news] 20080309 v1.0.13 and v1.1.rc3 released Source: CCN Type: GLSA-200803-25 Dovecot: Multiple vulnerabilities Source: CCN Type: OSVDB ID: 42979 Dovecot passdbs Argument Injection Authentication Bypass Source: BUGTRAQ Type: UNKNOWN 20080312 rPSA-2008-0108-1 dovecot Source: BID Type: UNKNOWN 28181 Source: CCN Type: BID-28181 Dovecot 'Tab' Character Password Check Security Bypass Vulnerability Source: CCN Type: USN-593-1 Dovecot vulnerabilities Source: XF Type: UNKNOWN dovecot-tab-authentication-bypass(41085) Source: XF Type: UNKNOWN dovecot-tab-authentication-bypass(41085) Source: CONFIRM Type: UNKNOWN https://issues.rpath.com/browse/RPL-2341 Source: UBUNTU Type: UNKNOWN USN-593-1 Source: EXPLOIT-DB Type: UNKNOWN 5257 Source: FEDORA Type: UNKNOWN FEDORA-2008-2464 Source: FEDORA Type: UNKNOWN FEDORA-2008-2475 Source: SUSE Type: SUSE-SR:2008:020 SUSE Security Summary Report | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |