CVE-2005-0198
EPSS 26.7%
Description
A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.
How to fix CVE-2005-0198
To remediate CVE-2005-0198, upgrade the affected package to a fixed version below.
- Debian/uw-imap—upgrade to 7:2002edebian1-6 or later
Is CVE-2005-0198 being exploited?
Moderate — EPSS is 26.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 7:2002edebian1-6