CVE Vulnerabilities

CVE-2008-1199

Published: Mar 06, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

Affected Software

Name Vendor Start Version End Version
Dovecot Dovecot 0.99.13 (including) 0.99.13 (including)
Dovecot Dovecot 0.99.14 (including) 0.99.14 (including)
Dovecot Dovecot 1.0 (including) 1.0 (including)
Dovecot Dovecot 1.0.2 (including) 1.0.2 (including)
Dovecot Dovecot 1.0.3 (including) 1.0.3 (including)
Dovecot Dovecot 1.0.4 (including) 1.0.4 (including)
Dovecot Dovecot 1.0.5 (including) 1.0.5 (including)
Dovecot Dovecot 1.0.6 (including) 1.0.6 (including)
Dovecot Dovecot 1.0.7 (including) 1.0.7 (including)
Dovecot Dovecot 1.0.8 (including) 1.0.8 (including)
Dovecot Dovecot 1.0.9 (including) 1.0.9 (including)
Dovecot Dovecot 1.0.10 (including) 1.0.10 (including)
Dovecot Dovecot 1.0.beta2 (including) 1.0.beta2 (including)
Dovecot Dovecot 1.0.beta3 (including) 1.0.beta3 (including)
Dovecot Dovecot 1.0.beta7 (including) 1.0.beta7 (including)
Dovecot Dovecot 1.0.beta8 (including) 1.0.beta8 (including)
Dovecot Dovecot 1.0.rc1 (including) 1.0.rc1 (including)
Dovecot Dovecot 1.0.rc2 (including) 1.0.rc2 (including)
Dovecot Dovecot 1.0.rc3 (including) 1.0.rc3 (including)
Dovecot Dovecot 1.0.rc4 (including) 1.0.rc4 (including)
Dovecot Dovecot 1.0.rc5 (including) 1.0.rc5 (including)
Dovecot Dovecot 1.0.rc6 (including) 1.0.rc6 (including)
Dovecot Dovecot 1.0.rc7 (including) 1.0.rc7 (including)
Dovecot Dovecot 1.0.rc8 (including) 1.0.rc8 (including)
Dovecot Dovecot 1.0.rc9 (including) 1.0.rc9 (including)
Dovecot Dovecot 1.0.rc10 (including) 1.0.rc10 (including)
Dovecot Dovecot 1.0.rc11 (including) 1.0.rc11 (including)
Dovecot Dovecot 1.0.rc12 (including) 1.0.rc12 (including)
Dovecot Dovecot 1.0.rc13 (including) 1.0.rc13 (including)
Dovecot Dovecot 1.0.rc14 (including) 1.0.rc14 (including)
Dovecot Dovecot 1.0.rc15 (including) 1.0.rc15 (including)
Dovecot Dovecot 1.0_rc29 (including) 1.0_rc29 (including)

References