CVE Vulnerabilities

CVE-2005-3532

Published: Dec 11, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.

Affected Software

NameVendorStart VersionEnd Version
Courier_mail_serverDouble_precision_incorporated0.37.3 (including)0.37.3 (including)
Courier_mail_serverDouble_precision_incorporated0.46 (including)0.46 (including)
Courier_mail_serverDouble_precision_incorporated0.47 (including)0.47 (including)
Courier_mail_serverDouble_precision_incorporated0.48 (including)0.48 (including)
Courier_mail_serverDouble_precision_incorporated0.48.1 (including)0.48.1 (including)
Courier_mail_serverDouble_precision_incorporated0.48.2 (including)0.48.2 (including)
Courier_mail_serverDouble_precision_incorporated0.49.0 (including)0.49.0 (including)
Courier_mail_serverDouble_precision_incorporated0.50.0 (including)0.50.0 (including)
Courier_mail_serverDouble_precision_incorporated0.52.1 (including)0.52.1 (including)

References