OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

imap-uw -- inappropriate user authentication (CRAM-MD5)

Affected packages
imap-uw < 2004.357

Details

VuXML ID a55ce9b2-720a-11d9-8a67-00065bd5b0b6
Discovery 2005-01-18
Entry 2005-01-29

A vulnerablility in an authentication method for the University of Washington IMAP server could allow a remote attacker to access any user's mailbox.

The Internet Message Access Protocol (IMAP) is a method of accessing electronic messages kept on a remote mail server and is specified in RFC3501. The University of Washington IMAP server features multiple user authentication methods, including the Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) as defined by RFC2195. A logic error in the code that handles CRAM-MD5 incorrectly specifies the conditions of successful authentication. This error results in a vulnerability that could allow a remote attacker to successfully authenticate as any user on the target system.

References

URL http://www.kb.cert.org/vuls/id/702777