Logo
vulnerabilityCVE-2005-0198
Name
CVE-2005-0198
Source
NVD ( link)Debian ( link)
Description
A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.
CWEs
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
uw-imap
Not Affected

Vulnerability Rating#


7.5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
2007f
Not Affected
yocto
master
2007f
Not Affected