Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6714 to the following vulnerability: DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication. References: http://www.mail-archive.com/dbmail-dev@dbmail.org/msg09942.html http://dbmail.org/index.php?page=news&id=44
dbmail-2.2.9-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
dbmail-2.2.9-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
dbmail-2.2.9-1.fc9 has been submitted as an update for Fedora 9
dbmail-2.2.9-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in: Fedora: https://admin.fedoraproject.org/updates/F7/FEDORA-2008-3371 https://admin.fedoraproject.org/updates/F8/FEDORA-2008-3333 https://admin.fedoraproject.org/updates/F9/FEDORA-2008-4245