CVE-2007-6598

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
04/01/2008
Last modified:
09/04/2025

Description

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* 1.0.9 (including)


References to Advisories, Solutions, and Tools