CVE-2007-6714

DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dbmail:dbmail:2.2.6:*:*:*:*:*:*:*
cpe:2.3:a:dbmail:dbmail:2.2.6:rc1:*:*:*:*:*:*
cpe:2.3:a:dbmail:dbmail:2.2.7:*:*:*:*:*:*:*
cpe:2.3:a:dbmail:dbmail:2.2.7:rc1:*:*:*:*:*:*
cpe:2.3:a:dbmail:dbmail:2.2.7:rc2:*:*:*:*:*:*
cpe:2.3:a:dbmail:dbmail:2.2.7:rc3:*:*:*:*:*:*
cpe:2.3:a:dbmail:dbmail:2.2.7:rc4:*:*:*:*:*:*
cpe:2.3:a:dbmail:dbmail:2.2.8:*:*:*:*:*:*:*
cpe:2.3:a:dbmail:dbmail:2.2.8:rc1:*:*:*:*:*:*

History

21 Nov 2024, 00:40

Type Values Removed Values Added
References () http://dbmail.org/index.php?page=news&id=44 - Patch () http://dbmail.org/index.php?page=news&id=44 - Patch
References () http://osvdb.org/44561 - () http://osvdb.org/44561 -
References () http://secunia.com/advisories/29903 - () http://secunia.com/advisories/29903 -
References () http://secunia.com/advisories/29937 - () http://secunia.com/advisories/29937 -
References () http://secunia.com/advisories/29984 - () http://secunia.com/advisories/29984 -
References () http://www.gentoo.org/security/en/glsa/glsa-200804-24.xml - () http://www.gentoo.org/security/en/glsa/glsa-200804-24.xml -
References () http://www.mail-archive.com/dbmail-dev%40dbmail.org/msg09942.html - () http://www.mail-archive.com/dbmail-dev%40dbmail.org/msg09942.html -
References () http://www.securityfocus.com/bid/28849 - () http://www.securityfocus.com/bid/28849 -
References () http://www.securitytracker.com/id?1019914 - () http://www.securitytracker.com/id?1019914 -
References () http://www.vupen.com/english/advisories/2008/1321/references - () http://www.vupen.com/english/advisories/2008/1321/references -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/41907 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/41907 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00549.html - () https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00549.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00585.html - () https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00585.html -

07 Nov 2023, 02:01

Type Values Removed Values Added
References
  • {'url': 'http://www.mail-archive.com/dbmail-dev@dbmail.org/msg09942.html', 'name': '[Dbmail-dev] 20071216 [DBMail 0000662]: Ability to bypass authentication.', 'tags': ['Exploit'], 'refsource': 'MLIST'}
  • () http://www.mail-archive.com/dbmail-dev%40dbmail.org/msg09942.html -

Information

Published : 2008-04-17 22:05

Updated : 2024-11-21 00:40


NVD link : CVE-2007-6714

Mitre link : CVE-2007-6714

CVE.ORG link : CVE-2007-6714


JSON object : View

Products Affected

dbmail

  • dbmail
CWE
CWE-287

Improper Authentication