Gentoo Linux Security Advisory GLSA 200804-24 – A vulnerability in DBMail’s authldap module when used in conjunction with an Active Directory server has been reported by vugluskr. When passing a zero length password to the module, it tries to bind anonymously to the LDAP server. If the LDAP server allows anonymous binds, this bind succeeds and results in a successful authentication to DBMail. Versions less than 2.2.9 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65671/glsa-200804-24.txt
Source: https://packetstormsecurity.com/files/65671/Gentoo-Linux-Security-Advisory-200804-24.html

