CVE-2008-1218

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
10/03/2008
Last modified:
09/04/2025

Description

Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* 1.0.12 (including)
cpe:2.3:a:dovecot:dovecot:*:rc2:*:*:*:*:*:* 1.1 (including)


References to Advisories, Solutions, and Tools