authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.
Link | Tags |
---|---|
http://www.debian.org/security/2005/dsa-917 | patch vendor advisory |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=211920 | patch |
http://secunia.com/advisories/17919 | third party advisory patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23532 | vdb entry |
http://www.securityfocus.com/bid/15771/ | vdb entry patch |
http://secunia.com/advisories/17999 | third party advisory |
https://usn.ubuntu.com/226-1/ | vendor advisory |