CVE-2007-6714
Summary
| CVE | CVE-2007-6714 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-04-17 22:05:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dbmail | Dbmail | 2.2.6 | All | All | All |
| Application | Dbmail | Dbmail | 2.2.6 | rc1 | All | All |
| Application | Dbmail | Dbmail | 2.2.7 | All | All | All |
| Application | Dbmail | Dbmail | 2.2.7 | rc1 | All | All |
| Application | Dbmail | Dbmail | 2.2.7 | rc2 | All | All |
| Application | Dbmail | Dbmail | 2.2.7 | rc3 | All | All |
| Application | Dbmail | Dbmail | 2.2.7 | rc4 | All | All |
| Application | Dbmail | Dbmail | 2.2.8 | All | All | All |
| Application | Dbmail | Dbmail | 2.2.8 | rc1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 8 Update: dbmail-2.2.9-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [SECURITY] Fedora 7 Update: dbmail-2.2.9-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| DBMail Empty LDAP Passwords Authentication Bypass - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for dbmail - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [Dbmail-dev] [DBMail 0000662]: Ability to bypass authentication. | af854a3a-2127-422b-91ae-364da2661108 | www.mail-archive.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo update for dbmail - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| DBMail LDAP Authentication Bug Lets Remote Users Access Arbitrary Mail Accounts - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| DBMail Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| DBMail: fast and scalable sql based mail services | af854a3a-2127-422b-91ae-364da2661108 | dbmail.org | Patch |
| osvdb.org/44561 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Gentoo Linux Documentation -- DBmail: Data disclosure | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| [Dbmail-dev] [DBMail 0000662]: Ability to bypass authentication. | MITRE | www.mail-archive.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.