Information Disclosure and Denial of Service in Evolution Data Server by Red Hat
CVE-2009-0582
Currently unrated
Summary
A flaw in the ntlm_challenge function within the NTLM SASL authentication mechanism of Evolution Data Server allows remote mail servers to exploit inconsistent length checks in challenge packets. This inadequacy can lead to unauthorized information being accessed from the client’s memory or cause application crashes, compromising both user security and system stability.
References
Timeline
Vulnerability published
Vulnerability Reserved