{ "schema_version": "1.4.0", "id": "GHSA-cr48-c784-cmxh", "modified": "2025-04-03T04:21:36Z", "published": "2022-05-01T02:18:59Z", "aliases": [ "CVE-2005-3532" ], "details": "authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-3532" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23532" }, { "type": "WEB", "url": "https://usn.ubuntu.com/226-1" }, { "type": "WEB", "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=211920" }, { "type": "WEB", "url": "http://secunia.com/advisories/17919" }, { "type": "WEB", "url": "http://secunia.com/advisories/17999" }, { "type": "WEB", "url": "http://www.debian.org/security/2005/dsa-917" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/15771" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2005-12-11T01:03:00Z" } }