A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.
References
Configurations
History
No history.
Information
Published : 2005-05-02 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2005-0198
Mitre link : CVE-2005-0198
CVE.ORG link : CVE-2005-0198
JSON object : View
Products Affected
university_of_washington
- uw-imap
CWE