Gentoo Linux Security Advisory GLSA 200804-24 - A vulnerability in DBMail's authldap module when used in conjunction with an Active Directory server has been reported by vugluskr. When passing a zero length password to the module, it tries to bind anonymously to the LDAP server. If the LDAP server allows anonymous binds, this bind succeeds and results in a successful authentication to DBMail. Versions less than 2.2.9 are affected.
fe44176bfcfe03ca8cc442fd07b97a05a599eebd360d1ecf7c08b76a0f4853a3