CVE-2005-3532
authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- double precision incorporated/courier mail server
- Source
- security@debian.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=211920Patch
- http://secunia.com/advisories/17919Patch, Vendor Advisory
- http://secunia.com/advisories/17999
- http://www.debian.org/security/2005/dsa-917Patch
- http://www.securityfocus.com/bid/15771/Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23532
- https://usn.ubuntu.com/226-1/
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=211920Patch
- http://secunia.com/advisories/17919Patch, Vendor Advisory
- http://secunia.com/advisories/17999
- http://www.debian.org/security/2005/dsa-917Patch
- http://www.securityfocus.com/bid/15771/Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23532
- https://usn.ubuntu.com/226-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.