cbcvebase.
CVE-2007-6598
published 2008-01-04

CVE-2007-6598: Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote…

PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.96%
78.2th percentile
Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:1.0.10-1 (bookworm)dovecot 1:1.0.10-1 (bookworm)
dovecotdovecot<= 1.0.9
dovecotdovecot>= 0 < 1:1.0.10-11:1.0.10-1
dovecotdovecot>= 0 < 1:1.0.10-11:1.0.10-1
dovecotdovecot>= 0 < 1:1.0.10-11:1.0.10-1
dovecotdovecot>= 0 < 1:1.0.10-11:1.0.10-1

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.