CVE-2006-2346: High severity Inter7 Vpopmail \(vchkpw\) vulnerability
Published May 12, 2006
·Updated
vpopmail 5.4.14 and 5.4.15, with cleartext passwords enabled, allows remote attackers to authenticate to an account that does not have a cleartext password set by using a blank password to (1) SMTP AUTH or (2) APOP.
Affected Software
2 affected components
Inter7 Vpopmail \(vchkpw\)=5.4.14
Inter7 Vpopmail \(vchkpw\)=5.4.15
Remediation
Patch Available
Patch Available
Event History
May 12, 2006
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2346?
CVE-2006-2346 is considered a critical vulnerability due to the potential for unauthorized access to accounts.
2
How does CVE-2006-2346 exploit affect vpopmail?
CVE-2006-2346 allows remote attackers to authenticate to accounts without cleartext passwords by using a blank password.
3
Which versions of vpopmail are affected by CVE-2006-2346?
CVE-2006-2346 affects vpopmail versions 5.4.14 and 5.4.15.
4
How do I fix CVE-2006-2346?
To fix CVE-2006-2346, disable cleartext passwords and upgrade to a patched version of vpopmail.
5
Can CVE-2006-2346 be exploited through SMTP AUTH or APOP?
Yes, CVE-2006-2346 can be exploited through both SMTP AUTH and APOP.