CVE-2008-1218: Medium severity dovecot vulnerability
Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skippasswordcheck field to be specified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1218?
CVE-2008-1218 is a high severity vulnerability that allows remote attackers to bypass password checks in Dovecot.
How do I fix CVE-2008-1218?
To fix CVE-2008-1218, upgrade Dovecot to version 1.0.13 or 1.1.rc3 and later.
What software is affected by CVE-2008-1218?
CVE-2008-1218 affects Dovecot versions 1.0.x before 1.0.13 and 1.1.x before 1.1.rc3.
Can CVE-2008-1218 lead to unauthorized access?
Yes, CVE-2008-1218 can allow attackers to gain unauthorized access by exploiting the argument injection flaw.
What specific method is exploited in CVE-2008-1218?
CVE-2008-1218 is exploited through the use of TAB characters in passwords, which manipulate how password checks are processed.