[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-1199Date: (C)2008-03-06   (M)2023-12-22


Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.4
Exploit Score: 3.4
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.securityfocus.com/archive/1/489133/100/0/threaded
BID-28092
SECUNIA-29226
SECUNIA-29385
SECUNIA-29396
SECUNIA-29557
SECUNIA-30342
SECUNIA-32151
DSA-1516
FEDORA-2008-2464
FEDORA-2008-2475
GLSA-200803-25
RHSA-2008:0297
SUSE-SR:2008:020
USN-593-1
http://www.dovecot.org/list/dovecot-news/2008-March/000061.html
dovecot-mailextragroups-unauth-access(41009)
oval:org.mitre.oval:def:10739

CWE    1
CWE-16
OVAL    1
oval:org.mitre.oval:def:8054

© SecPod Technologies