A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Uw-imap | University_of_washington | * | * |
| Red Hat Enterprise Linux 3 | RedHat | imap-1:2002d-11 | * |
| Uw-imap | Ubuntu | dapper | * |
| Uw-imap | Ubuntu | devel | * |
| Uw-imap | Ubuntu | edgy | * |
| Uw-imap | Ubuntu | feisty | * |