A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Uw-imap | University_of_washington | * | * |
Uw-imap | Ubuntu | dapper | * |
Uw-imap | Ubuntu | devel | * |
Uw-imap | Ubuntu | edgy | * |
Uw-imap | Ubuntu | feisty | * |
Red Hat Enterprise Linux 3 | RedHat | imap-1:2002d-11 | * |