Bug#458315: LDAP + auth cache authentication vulnerability

2007-12-30 Thread Thijs Kinkhorst
On Sunday 30 December 2007 12:49, Fabio Tranchitella wrote: > We must issue a DSA. > > I've already backported the patch and rebuilt the package, but I don't have > time to test it till next week. I suppose the package is fine (it is a two > lines patch, and it compiles fine), but I think we should

Bug#458315: LDAP + auth cache authentication vulnerability

2007-12-30 Thread Fabio Tranchitella
Hello, * 2007-12-30 11:38, Thijs Kinkhorst wrote: > Package: dovecot > Version: 1.0.rc15-2etch1 > Tags: security > Severity: important > > Hi, > > A security issue has been discovered in Dovecot: > http://dovecot.org/list/dovecot-news/2007-December/57.html We must issue a DSA. I've already

Bug#458315: LDAP + auth cache authentication vulnerability

2007-12-30 Thread Thijs Kinkhorst
Package: dovecot Version: 1.0.rc15-2etch1 Tags: security Severity: important Hi, A security issue has been discovered in Dovecot: http://dovecot.org/list/dovecot-news/2007-December/57.html Users can be presented with wrong mailboxes if they have the same password as another issue. Since it