CVE-2005-3532
Published Dec 11, 2005
Last updated 6 years ago
Overview
- Description
- authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.
- Source
- security@debian.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:double_precision_incorporated:courier_mail_server:0.37.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1B758F4-32EF-43B1-A0F1-E54D9C050BEF" }, { "criteria": "cpe:2.3:a:double_precision_incorporated:courier_mail_server:0.46:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB82816F-11B7-40C3-AF80-C3091372C46D" }, { "criteria": "cpe:2.3:a:double_precision_incorporated:courier_mail_server:0.47:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B66C6966-7500-432C-A766-35FAA9E42FAE" }, { "criteria": "cpe:2.3:a:double_precision_incorporated:courier_mail_server:0.48:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B082F880-5684-4FB5-B469-A5B65847D577" }, { "criteria": "cpe:2.3:a:double_precision_incorporated:courier_mail_server:0.48.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A23AE92-D4C0-4F7C-85DC-BC3A9B7D53A1" }, { "criteria": "cpe:2.3:a:double_precision_incorporated:courier_mail_server:0.48.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0CFFC62C-4969-405E-8F2C-E3D31DDED5C5" }, { "criteria": "cpe:2.3:a:double_precision_incorporated:courier_mail_server:0.49.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "21FEF102-4961-4AA0-969F-4108E4556CEA" }, { "criteria": "cpe:2.3:a:double_precision_incorporated:courier_mail_server:0.50.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E387763-BAA3-4353-8065-DBB99CFC94B2" }, { "criteria": "cpe:2.3:a:double_precision_incorporated:courier_mail_server:0.52.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF1D6D6B-BA9B-493B-9E0A-43A55AA8766B" } ], "operator": "OR" } ] } ]