PT-2022-16837 · Maddy+1 · Maddy+1

Sysf

·

Published

2022-03-07

·

Updated

2022-03-17

·

CVE-2022-24732

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions maddy versions prior to 0.5.4
Description The issue concerns the Maddy Mail Server, an open source SMTP compatible email server. It does not implement password expiry or account expiry checking when authenticating using PAM. This affects configurations using auth.pam on versions prior to 0.5.4. Users are advised to upgrade to address the issue. For those unable to upgrade, manually removing expired accounts via existing filtering mechanisms is recommended.
Recommendations For versions prior to 0.5.4, upgrade to version 0.5.4 or later to resolve the issue. As a temporary workaround, consider replacing auth.pam with auth.shadow if /etc/shadow authentication is used. Alternatively, blacklist expired accounts via existing filtering mechanisms, such as using auth map to invalid accounts in storage.imapsql.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24732
GHSA-6CP7-G972-W9M9

Affected Products

Maddy Mail Server
Maddy