University Of Washington IMAP Server CRAM-MD5 Remote Authentication Bypass Vulnerability

BID:12391

Info

University Of Washington IMAP Server CRAM-MD5 Remote Authentication Bypass Vulnerability

Bugtraq ID: 12391
Class: Design Error
CVE: CVE-2005-0198
Remote: Yes
Local: No
Published: Jan 28 2005 12:00AM
Updated: Jul 12 2009 10:06AM
Credit: Mark Crispin and Hugh Sheets of the University of Washington are credited with disclosing this issue.
Vulnerable: University of Washington imap 2004b
+ Gentoo Linux
University of Washington imap 2004a
+ S.u.S.E. Linux Personal 9.2 x86_64
+ S.u.S.E. Linux Personal 9.2
University of Washington imap 2004
University of Washington imap 2002e
+ S.u.S.E. Linux Personal 9.1 x86_64
+ S.u.S.E. Linux Personal 9.1
University of Washington imap 2002d
+ MandrakeSoft Corporate Server 3.0 x86_64
+ MandrakeSoft Corporate Server 3.0
+ Mandriva Linux Mandrake 10.1 x86_64
+ Mandriva Linux Mandrake 10.1
+ Mandriva Linux Mandrake 10.0 AMD64
+ Mandriva Linux Mandrake 10.0
+ Redhat Desktop 3.0
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 3
+ S.u.S.E. Linux Personal 9.0 x86_64
+ S.u.S.E. Linux Personal 9.0
University of Washington imap 2002c
University of Washington imap 2002b
University of Washington imap 2002
+ S.u.S.E. Linux Personal 8.2
Turbolinux Turbolinux Workstation 8.0
Turbolinux Turbolinux Workstation 7.0
Turbolinux Turbolinux Server 10.0
Turbolinux Turbolinux Server 8.0
Turbolinux Turbolinux Server 7.0
Turbolinux Turbolinux Desktop 10.0
Turbolinux Home
Turbolinux Appliance Server 1.0 Workgroup Edition
Turbolinux Appliance Server 1.0 Hosting Edition
SuSE SUSE Linux Enterprise Server 8
+ Linux kernel 2.4.21
+ Linux kernel 2.4.19
SuSE SUSE Linux Enterprise Server 7
+ Linux kernel 2.4.19
SuSE Linux Enterprise Server 9
SuSE Linux Desktop 1.0
SuSE Linux 8.1
SuSE Linux 8.0 i386
SuSE Linux 8.0
SGI Advanced Linux Environment 3.0
S.u.S.E. Linux Personal 9.2 x86_64
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1 x86_64
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 8.2
Redhat Linux 9.0 i386
Redhat Linux 7.3 i686
Redhat Linux 7.3 i386
Redhat Linux 7.3
Redhat Fedora Core1
Not Vulnerable: University of Washington imap 2004c

Discussion

University Of Washington IMAP Server CRAM-MD5 Remote Authentication Bypass Vulnerability

A remote authentication bypass vulnerability affects the CRAM-MD5 authentication functionality of the University of Washington IMAP server. This issue is due to a logic error that fails to properly validate authentication attempts.

It should be noted that this issue only affects servers with CRAM-MD5 authentication enabled, which is not the case by default.

A remote attacker may leverage this issue to authenticate to the affected server as any user.

Exploit / POC

University Of Washington IMAP Server CRAM-MD5 Remote Authentication Bypass Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

University Of Washington IMAP Server CRAM-MD5 Remote Authentication Bypass Vulnerability

Solution:
The vendor has released an upgrade dealing with this issue.

Turbolinux has made an advisory available (TLSA-2005-32) dealing with this issue. Please see the referenced advisory for more information.

Mandrake linux has made an advisory available (MDKSA-2005:026) dealing with this issue. Please see the referenced advisory for more information.

Gentoo linux has made advisory GLSA 200502-02 available dealing with this issue. Gentoo advises that all UW IMAP users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-mail/uw-imap-2004b"

For more information please see the referenced Gentoo advisory.

Red Hat has released advisory RHSA-2005:128-06 to address this issue in Red Hat Enterprise Linux 3. Please see the advisory in Web references for more information.

SuSE has released summary report SUSE-SR:2005:006 mainly to address vulnerabilities described in other BIDs. However, in the addendum of this advisory, it is reported that fixes for the issues described in this BID are pending release. Customers are advised to see the referenced advisory for further information.

SuSE Linux has released advisory SUSE-SA:2005:012 along with fixes dealing with this issue. Please see the referenced advisory for more information.

Silicon Graphics has released advisory 20050301-01-U dealing with this and other issues for their Advanced Linux Environment packages. Please see the referenced advisories for more information.

The Fedora Legacy project has released advisory FLSA:152912 to address this issue in RedHat Linux 7.3, 9, and Fedora Core 1. Please see the referenced advisory for further information.


University of Washington imap 2002b

University of Washington imap 2004

University of Washington imap 2004a

University of Washington imap 2002

University of Washington imap 2002c

University of Washington imap 2002e

University of Washington imap 2002d

University of Washington imap 2004b

References

University Of Washington IMAP Server CRAM-MD5 Remote Authentication Bypass Vulnerability

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report