漏洞信息详情
University Of Washington IMAP Server CRAM-MD5远程身份验证绕过漏洞
- CNNVD编号:CNNVD-200505-445
- 危害等级: 高危
- CVE编号:
CVE-2005-0198
- 漏洞类型:
设计错误
- 发布时间:
2005-05-02
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
university_of_washington - 漏洞来源:
Mark Crispin and H… -
漏洞简介
University of Washington IMAP (UW-IMAP) server的CRAM-MD5代码中存在逻辑错误,在启用\”口令-应答认证机制\”MD5 (CRAM-MD5)的情况下,并不能针对成功的身份验证正确强制所有要求的条件,从而远程攻击者可以作为任意用户进行身份验证。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
University of Washington imap 2002b
TurboLinux imap-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/imap-2002b-11.i586.rpm
TurboLinux imap-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/imap-2002b-11.i586.rpm
TurboLinux imap-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/imap-2002b-11.i586.rpm
TurboLinux imap-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/imap-2002b-11.i586.rpm
TurboLinux imap-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/imap-2002b-11.i586.rpm
TurboLinux imap-devel-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/imap-devel-2002b-11.i586.rpm
TurboLinux imap-devel-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/imap-devel-2002b-11.i586.rpm
TurboLinux imap-devel-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/imap-devel-2002b-11.i586.rpm
TurboLinux imap-devel-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/imap-devel-2002b-11.i586.rpm
TurboLinux imap-devel-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/imap-devel-2002b-11.i586.rpm
TurboLinux imap-libs-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/imap-libs-2002b-11.i586.rpm
TurboLinux imap-libs-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/imap-libs-2002b-11.i586.rpm
TurboLinux imap-libs-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/imap-libs-2002b-11.i586.rpm
TurboLinux imap-libs-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/imap-libs-2002b-11.i586.rpm
TurboLinux imap-libs-2002b-11.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/imap-libs-2002b-11.i586.rpm
University of Washington UW-imap 2004c
ftp://ftp.cac.washington.edu/mail/imap.tar.Z
University of Washington imap 2004
Mandrake imap-2004-2.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake imap-2004-2.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Mandrake imap-devel-2004-2.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake imap-devel-2004-2.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Mandrake imap-utils-2004-2.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake imap-utils-2004-2.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Mandrake lib64c-client-php0-2004-2.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Mandrake lib64c-client-php0-devel-2004-2.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Mandrake libc-client-php0-2004-2.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake libc-client-php0-devel-2004-2.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php
University of Washington UW-imap 2004c
ftp://ftp.cac.washington.edu/mail/imap.tar.Z
University of Washington imap 2004a
SuSE imap-2004a-3.2.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/imap-2004a-3.2.i5 86.rpm
SuSE imap-2004a-3.2.x86_64.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/imap-2004a-3.2. x86_64.rpm
TurboLinux imap-2004a-5.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/10/up dates/RPMS/imap-2004a-5.i586.rpm
TurboL
参考网址
来源: US-CERT
链接:http://www.kb.cert.org/vuls/id/CRDY-68QSL5
来源:US-CERT
名称: VU#702777
链接:http://www.kb.cert.org/vuls/id/702777
来源: REDHAT
名称: RHSA-2005:128
链接:http://www.redhat.com/support/errata/RHSA-2005-128.html
来源: GENTOO
名称: GLSA-200502-02
链接:http://www.gentoo.org/security/en/glsa/glsa-200502-02.xml
来源: BID
名称: 12391
链接:http://www.securityfocus.com/bid/12391
来源: MANDRAKE
名称: MDKSA-2005:026
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:026
来源: SECTRACK
名称: 1013037
链接:http://securitytracker.com/id?1013037
来源: SECUNIA
名称: 14097
链接:http://secunia.com/advisories/14097
来源: SECUNIA
名称: 14057