Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dovecot | Jul 30, 2024 | Jan 4, 2008 |
| Oracle_linux | — | Upgrade dovecot | Oct 16, 2024 | Jan 4, 2008 |
| Suse | — | Upgrade dovecot-develUpgrade dovecotUpgrade suse-release | Feb 17, 2015 | Jan 3, 2008 |
| Ubuntu | — | Upgrade dovecot-imapdUpgrade dovecot-pop3d | Nov 8, 2024 | Jan 4, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub