The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.
References
Link Providers
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc cve-icon cve-icon
http://balsa.gnome.org/download.html cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=305530 cve-icon cve-icon
http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2007/May/msg00004.html cve-icon cve-icon
http://mail.gnome.org/archives/balsa-list/2007-July/msg00000.html cve-icon cve-icon
http://secunia.com/advisories/25353 cve-icon cve-icon
http://secunia.com/advisories/25402 cve-icon cve-icon
http://secunia.com/advisories/25476 cve-icon cve-icon
http://secunia.com/advisories/25496 cve-icon cve-icon
http://secunia.com/advisories/25529 cve-icon cve-icon
http://secunia.com/advisories/25534 cve-icon cve-icon
http://secunia.com/advisories/25546 cve-icon cve-icon
http://secunia.com/advisories/25559 cve-icon cve-icon
http://secunia.com/advisories/25664 cve-icon cve-icon
http://secunia.com/advisories/25750 cve-icon cve-icon
http://secunia.com/advisories/25798 cve-icon cve-icon
http://secunia.com/advisories/25858 cve-icon cve-icon
http://secunia.com/advisories/25894 cve-icon cve-icon
http://secunia.com/advisories/26083 cve-icon cve-icon
http://secunia.com/advisories/26415 cve-icon cve-icon
http://secunia.com/advisories/35699 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200706-06.xml cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.571857 cve-icon cve-icon
http://sourceforge.net/forum/forum.php?forum_id=683706 cve-icon cve-icon
http://sylpheed.sraoss.jp/en/news.html cve-icon cve-icon
http://www.claws-mail.org/news.php cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1300 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1305 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:105 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:107 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:113 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:119 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:131 cve-icon cve-icon
http://www.mozilla.org/security/announce/2007/mfsa2007-15.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_14_sr.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_36_mozilla.html cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2009/08/15/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2009/08/18/1 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0344.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0353.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0385.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0386.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0401.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0402.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2009-1140.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/464477/30/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/464569/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/470172/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/471455/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/471720/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/471842/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/23257 cve-icon cve-icon
http://www.securitytracker.com/id?1018008 cve-icon cve-icon
http://www.trustix.org/errata/2007/0019/ cve-icon cve-icon
http://www.trustix.org/errata/2007/0024/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-469-1 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-520-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-151A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1466 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1467 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1468 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1480 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1939 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1994 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2788 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0082 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1231 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1232 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1424 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-1558 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9782 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-1558 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-04-16T22:00:00

Updated: 2024-08-07T12:59:08.708Z

Reserved: 2007-03-20T00:00:00

Link: CVE-2007-1558

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-04-16T22:19:00.000

Modified: 2018-10-16T16:39:13.097

Link: CVE-2007-1558

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-04-02T00:00:00Z

Links: CVE-2007-1558 - Bugzilla