Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.53002
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: imap-uw
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: imap-uw

CVE-2005-0198
A logic error in the CRAM-MD5 code for the University of Washington
IMAP (UW-IMAP) server, when Challenge-Response Authentication
Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce
all the required conditions for successful authentication, which
allows remote attackers to authenticate as arbitrary users.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2005-0198
BugTraq ID: 12391
http://www.securityfocus.com/bid/12391
CERT/CC vulnerability note: VU#702777
http://www.kb.cert.org/vuls/id/702777
http://www.gentoo.org/security/en/glsa/glsa-200502-02.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2005:026
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11306
http://www.redhat.com/support/errata/RHSA-2005-128.html
http://securitytracker.com/id?1013037
http://secunia.com/advisories/14057
http://secunia.com/advisories/14097
CopyrightCopyright (C) 2008 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.