DEBIAN-CVE-2005-0198

Source
https://security-tracker.debian.org/tracker/CVE-2005-0198
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2005-0198.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2005-0198
Upstream
Published
2005-05-02T04:00:00Z
Modified
2025-11-19T01:06:25.522040Z
Summary
[none]
Details

A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.

References

Affected packages

Debian:11 / uw-imap

Package

Name
uw-imap
Purl
pkg:deb/debian/uw-imap?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7:2002edebian1-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2005-0198.json"

Debian:12 / uw-imap

Package

Name
uw-imap
Purl
pkg:deb/debian/uw-imap?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7:2002edebian1-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2005-0198.json"