CVE-2007-6598

Publication date 4 January 2008

Last updated 24 July 2024


Ubuntu priority

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

Status

Package Ubuntu Release Status
dovecot 7.10 gutsy
Fixed 1:1.0.5-1ubuntu2.1
7.04 feisty
Fixed 1.0.rc17-1ubuntu2.2
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
dovecot

References

Related Ubuntu Security Notices (USN)

    • USN-567-1
    • Dovecot vulnerability
    • 10 January 2008

Other references