University Of Washington IMAP Server CRAM-MD5远程身份验证绕过漏洞

漏洞信息详情

University Of Washington IMAP Server CRAM-MD5远程身份验证绕过漏洞

漏洞简介

University of Washington IMAP (UW-IMAP) server的CRAM-MD5代码中存在逻辑错误,在启用\”口令-应答认证机制\”MD5 (CRAM-MD5)的情况下,并不能针对成功的身份验证正确强制所有要求的条件,从而远程攻击者可以作为任意用户进行身份验证。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

University of Washington imap 2002b

TurboLinux imap-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/imap-2002b-11.i586.rpm

TurboLinux imap-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/imap-2002b-11.i586.rpm

TurboLinux imap-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/imap-2002b-11.i586.rpm

TurboLinux imap-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/imap-2002b-11.i586.rpm

TurboLinux imap-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/imap-2002b-11.i586.rpm

TurboLinux imap-devel-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/imap-devel-2002b-11.i586.rpm

TurboLinux imap-devel-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/imap-devel-2002b-11.i586.rpm

TurboLinux imap-devel-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/imap-devel-2002b-11.i586.rpm

TurboLinux imap-devel-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/imap-devel-2002b-11.i586.rpm

TurboLinux imap-devel-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/imap-devel-2002b-11.i586.rpm

TurboLinux imap-libs-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/imap-libs-2002b-11.i586.rpm

TurboLinux imap-libs-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/imap-libs-2002b-11.i586.rpm

TurboLinux imap-libs-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/imap-libs-2002b-11.i586.rpm

TurboLinux imap-libs-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/imap-libs-2002b-11.i586.rpm

TurboLinux imap-libs-2002b-11.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/imap-libs-2002b-11.i586.rpm

University of Washington UW-imap 2004c

ftp://ftp.cac.washington.edu/mail/imap.tar.Z

University of Washington imap 2004

Mandrake imap-2004-2.1.101mdk.i586.rpm

Mandrake Linux 10.1

http://www.mandrakesecure.net/en/ftp.php

Mandrake imap-2004-2.1.101mdk.x86_64.rpm

Mandrake Linux 10.1/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake imap-devel-2004-2.1.101mdk.i586.rpm

Mandrake Linux 10.1

http://www.mandrakesecure.net/en/ftp.php

Mandrake imap-devel-2004-2.1.101mdk.x86_64.rpm

Mandrake Linux 10.1/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake imap-utils-2004-2.1.101mdk.i586.rpm

Mandrake Linux 10.1

http://www.mandrakesecure.net/en/ftp.php

Mandrake imap-utils-2004-2.1.101mdk.x86_64.rpm

Mandrake Linux 10.1/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake lib64c-client-php0-2004-2.1.101mdk.x86_64.rpm

Mandrake Linux 10.1/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake lib64c-client-php0-devel-2004-2.1.101mdk.x86_64.rpm

Mandrake Linux 10.1/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake libc-client-php0-2004-2.1.101mdk.i586.rpm

Mandrake Linux 10.1

http://www.mandrakesecure.net/en/ftp.php

Mandrake libc-client-php0-devel-2004-2.1.101mdk.i586.rpm

Mandrake Linux 10.1

http://www.mandrakesecure.net/en/ftp.php

University of Washington UW-imap 2004c

ftp://ftp.cac.washington.edu/mail/imap.tar.Z

University of Washington imap 2004a

SuSE imap-2004a-3.2.i586.rpm

ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/imap-2004a-3.2.i5 86.rpm

SuSE imap-2004a-3.2.x86_64.rpm

ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/imap-2004a-3.2. x86_64.rpm

TurboLinux imap-2004a-5.i586.rpm

ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/10/up dates/RPMS/imap-2004a-5.i586.rpm

TurboL

参考网址

来源: US-CERT

链接:http://www.kb.cert.org/vuls/id/CRDY-68QSL5

来源:US-CERT

名称: VU#702777

链接:http://www.kb.cert.org/vuls/id/702777

来源: REDHAT

名称: RHSA-2005:128

链接:http://www.redhat.com/support/errata/RHSA-2005-128.html

来源: GENTOO

名称: GLSA-200502-02

链接:http://www.gentoo.org/security/en/glsa/glsa-200502-02.xml

来源: BID

名称: 12391

链接:http://www.securityfocus.com/bid/12391

来源: MANDRAKE

名称: MDKSA-2005:026

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:026

来源: SECTRACK

名称: 1013037

链接:http://securitytracker.com/id?1013037

来源: SECUNIA

名称: 14097

链接:http://secunia.com/advisories/14097

来源: SECUNIA

名称: 14057

链接:http://secunia.com/advisories/14057

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享