CVE Vulnerabilities

CVE-2007-1558

Published: Apr 16, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
2.6 MODERATE
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
UNTRIAGED

The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.

Affected Software

Name Vendor Start Version End Version
Apop_protocol Apop_protocol * *
Red Hat Enterprise Linux 2.1 RedHat fetchmail-0:5.9.0-21.7.3.el2.1.6 *
Red Hat Enterprise Linux 2.1 RedHat seamonkey-0:1.0.9-0.1.el2 *
Red Hat Enterprise Linux 3 RedHat evolution-0:1.4.5-20.el3 *
Red Hat Enterprise Linux 3 RedHat fetchmail-0:6.2.0-3.el3.4 *
Red Hat Enterprise Linux 3 RedHat mutt-5:1.4.1-5.el3 *
Red Hat Enterprise Linux 3 RedHat seamonkey-0:1.0.9-0.1.el3 *
Red Hat Enterprise Linux 4 RedHat evolution-0:2.0.2-35.0.2.el4 *
Red Hat Enterprise Linux 4 RedHat fetchmail-0:6.2.5-6.0.1.el4 *
Red Hat Enterprise Linux 4 RedHat mutt-5:1.4.1-12.0.3.el4 *
Red Hat Enterprise Linux 4 RedHat thunderbird-0:1.5.0.12-0.1.el4 *
Red Hat Enterprise Linux 4 RedHat devhelp-0:0.10-0.8.el4 *
Red Hat Enterprise Linux 4 RedHat seamonkey-0:1.0.9-2.el4 *
Red Hat Enterprise Linux 4 RedHat ruby-0:1.8.1-7.el4_8.3 *
Red Hat Enterprise Linux 5 RedHat evolution-data-server-0:1.8.0-15.0.3.el5 *
Red Hat Enterprise Linux 5 RedHat fetchmail-0:6.3.6-1.0.1.el5 *
Red Hat Enterprise Linux 5 RedHat mutt-5:1.4.2.2-3.0.2.el5 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:1.5.0.12-1.el5 *
Red Hat Enterprise Linux 5 RedHat ruby-0:1.8.5-5.el5_3.7 *
Fetchmail Ubuntu dapper *
Fetchmail Ubuntu devel *
Fetchmail Ubuntu edgy *
Fetchmail Ubuntu feisty *
Iceape Ubuntu devel *
Im Ubuntu dapper *
Im Ubuntu devel *
Im Ubuntu edgy *
Im Ubuntu feisty *
Mew Ubuntu dapper *
Mew Ubuntu devel *
Mew Ubuntu edgy *
Mew Ubuntu feisty *
Mew-beta Ubuntu dapper *
Mew-beta Ubuntu devel *
Mew-beta Ubuntu edgy *
Mew-beta Ubuntu feisty *
Mozilla-thunderbird Ubuntu dapper *
Mozilla-thunderbird Ubuntu edgy *
Mozilla-thunderbird Ubuntu feisty *
Wl Ubuntu dapper *
Wl Ubuntu devel *
Wl Ubuntu edgy *
Wl Ubuntu feisty *
Wl-beta Ubuntu dapper *
Wl-beta Ubuntu devel *
Wl-beta Ubuntu edgy *
Wl-beta Ubuntu feisty *

References