|
|
Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2005:026: imap Vulnerability Scan
Vulnerability Scan Summary Check for the version of the imap package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2005:026 (imap).
A vulnerability was discovered in the CRAM-MD5 authentication in UW-IMAP where,
on the fourth failed authentication attempt, a user would be able to access the
IMAP server regardless. This problem exists only if you are using CRAM-MD5
authentication and have an /etc/cram-md5.pwd file. This is not the default
setup.
The updated packages have been patched to prevent these problems.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:026
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|