CVE-2007-6598

Impact:
Low
Public Date:
2007-12-29
Bugzilla:
427575: CVE-2007-6598 dovecot LDAP+auth cache user login mixup

The MITRE CVE dictionary describes this issue as:

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

Find out more about CVE-2007-6598 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect versions of Dovecot as shipped with Red Hat Enterprise Linux before version 5. An update to Red Hat Enterprise Linux 5 was released to correct this issue:
https://rhn.redhat.com/errata/RHSA-2008-0297.html

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (dovecot) RHSA-2008:0297 2008-05-20

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.