CVE Vulnerabilities

CVE-2008-1199

Published: Mar 06, 2008 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

Affected Software

Name Vendor Start Version End Version
Dovecot Dovecot 0.99.13 (including) 0.99.13 (including)
Dovecot Dovecot 0.99.14 (including) 0.99.14 (including)
Dovecot Dovecot 1.0 (including) 1.0 (including)
Dovecot Dovecot 1.0.2 (including) 1.0.2 (including)
Dovecot Dovecot 1.0.3 (including) 1.0.3 (including)
Dovecot Dovecot 1.0.4 (including) 1.0.4 (including)
Dovecot Dovecot 1.0.5 (including) 1.0.5 (including)
Dovecot Dovecot 1.0.6 (including) 1.0.6 (including)
Dovecot Dovecot 1.0.7 (including) 1.0.7 (including)
Dovecot Dovecot 1.0.8 (including) 1.0.8 (including)
Dovecot Dovecot 1.0.9 (including) 1.0.9 (including)
Dovecot Dovecot 1.0.10 (including) 1.0.10 (including)
Dovecot Dovecot 1.0.beta2 (including) 1.0.beta2 (including)
Dovecot Dovecot 1.0.beta3 (including) 1.0.beta3 (including)
Dovecot Dovecot 1.0.beta7 (including) 1.0.beta7 (including)
Dovecot Dovecot 1.0.beta8 (including) 1.0.beta8 (including)
Dovecot Dovecot 1.0.rc1 (including) 1.0.rc1 (including)
Dovecot Dovecot 1.0.rc2 (including) 1.0.rc2 (including)
Dovecot Dovecot 1.0.rc3 (including) 1.0.rc3 (including)
Dovecot Dovecot 1.0.rc4 (including) 1.0.rc4 (including)
Dovecot Dovecot 1.0.rc5 (including) 1.0.rc5 (including)
Dovecot Dovecot 1.0.rc6 (including) 1.0.rc6 (including)
Dovecot Dovecot 1.0.rc7 (including) 1.0.rc7 (including)
Dovecot Dovecot 1.0.rc8 (including) 1.0.rc8 (including)
Dovecot Dovecot 1.0.rc9 (including) 1.0.rc9 (including)
Dovecot Dovecot 1.0.rc10 (including) 1.0.rc10 (including)
Dovecot Dovecot 1.0.rc11 (including) 1.0.rc11 (including)
Dovecot Dovecot 1.0.rc12 (including) 1.0.rc12 (including)
Dovecot Dovecot 1.0.rc13 (including) 1.0.rc13 (including)
Dovecot Dovecot 1.0.rc14 (including) 1.0.rc14 (including)
Dovecot Dovecot 1.0.rc15 (including) 1.0.rc15 (including)
Dovecot Dovecot 1.0_rc29 (including) 1.0_rc29 (including)
Red Hat Enterprise Linux 5 RedHat dovecot-0:1.0.7-2.el5 *
Dovecot Ubuntu dapper *
Dovecot Ubuntu devel *
Dovecot Ubuntu edgy *
Dovecot Ubuntu feisty *
Dovecot Ubuntu gutsy *
Dovecot Ubuntu upstream *

References