CVE-2007-6598

Description

From CVE.org

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

Statement

This issue did not affect versions of Dovecot as shipped with Red Hat Enterprise Linux before version 5.

Frequently Asked Questions

Want to get errata notifications? Sign up here.