The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
21 Nov 2024, 00:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.gentoo.org/show_bug.cgi?id=240409 - Issue Tracking | |
References | () http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html - Mailing List | |
References | () http://secunia.com/advisories/32164 - Broken Link, Vendor Advisory | |
References | () http://secunia.com/advisories/32471 - Broken Link | |
References | () http://secunia.com/advisories/33149 - Broken Link | |
References | () http://secunia.com/advisories/33624 - Broken Link | |
References | () http://secunia.com/advisories/36904 - Broken Link | |
References | () http://security.gentoo.org/glsa/glsa-200812-16.xml - Third Party Advisory | |
References | () http://www.dovecot.org/list/dovecot-news/2008-October/000085.html - Mailing List, Release Notes | |
References | () http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2009-0205.html - Broken Link | |
References | () http://www.securityfocus.com/bid/31587 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.ubuntu.com/usn/USN-838-1 - Third Party Advisory | |
References | () http://www.vupen.com/english/advisories/2008/2745 - Permissions Required | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 - Broken Link | |
References | () https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html - Mailing List | |
References | () https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html - Mailing List |
21 Jan 2024, 02:46
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.4
v3 : 7.5 |
CWE | CWE-863 | |
References | (CONFIRM) http://bugs.gentoo.org/show_bug.cgi?id=240409 - Issue Tracking | |
References | (SECUNIA) http://secunia.com/advisories/36904 - Broken Link | |
References | (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 - Broken Link | |
References | (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 - Broken Link | |
References | (BID) http://www.securityfocus.com/bid/31587 - Broken Link, Third Party Advisory, VDB Entry | |
References | (SECUNIA) http://secunia.com/advisories/32471 - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/33149 - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/33624 - Broken Link | |
References | (VUPEN) http://www.vupen.com/english/advisories/2008/2745 - Permissions Required | |
References | (SECUNIA) http://secunia.com/advisories/32164 - Broken Link, Vendor Advisory | |
References | (UBUNTU) http://www.ubuntu.com/usn/USN-838-1 - Third Party Advisory | |
References | (MLIST) http://www.dovecot.org/list/dovecot-news/2008-October/000085.html - Mailing List, Release Notes | |
References | (FEDORA) https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html - Mailing List | |
References | (GENTOO) http://security.gentoo.org/glsa/glsa-200812-16.xml - Third Party Advisory | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2009-0205.html - Broken Link | |
References | (FEDORA) https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html - Mailing List | |
References | (SUSE) http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html - Mailing List | |
First Time |
Fedoraproject fedora
Canonical ubuntu Linux Fedoraproject Canonical Opensuse opensuse Opensuse |
|
CPE | cpe:2.3:a:dovecot:dovecot:1.0.rc22:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc25:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.6:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.10:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.beta1:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0_rc29:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.12:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc13:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc23:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.8:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc9:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc21:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc17:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc5:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc10:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc20:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.beta8:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.beta3:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.7:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc6:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.1:rc2:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.3:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc8:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc28:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc2:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.beta9:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.5:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.1.2:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc15:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc7:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc19:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc14:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.2:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.beta7:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc3:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.1.0:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc18:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc4:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:0.99.14:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc12:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc1:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.1.1:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:0.99.13:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc27:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.beta6:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.beta5:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc24:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc16:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.beta2:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.1:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.4:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.beta4:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc11:*:*:*:*:*:*:* cpe:2.3:a:dovecot:dovecot:1.0.rc26:*:*:*:*:*:*:* |
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:* cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:* cpe:2.3:o:opensuse:opensuse:10.3-11.1:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:* |
Information
Published : 2008-10-15 20:08
Updated : 2024-11-21 00:52
NVD link : CVE-2008-4577
Mitre link : CVE-2008-4577
CVE.ORG link : CVE-2008-4577
JSON object : View
Products Affected
dovecot
- dovecot
fedoraproject
- fedora
canonical
- ubuntu_linux
opensuse
- opensuse
CWE
CWE-863
Incorrect Authorization