GLSA-200804-24 : DBmail: Data disclosure
Medium Nessus Plugin ID 32017
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200804-24 (DBmail: Data disclosure)
A vulnerability in DBMail's authldap module when used in conjunction with an Active Directory server has been reported by vugluskr. When passing a zero length password to the module, it tries to bind anonymously to the LDAP server. If the LDAP server allows anonymous binds, this bind succeeds and results in a successful authentication to DBMail.
By passing an empty password string to the server, an attacker could be able to log in to any account.
There is no known workaround at this time.
SolutionAll DBMail users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-mail/dbmail-2.2.9'