CVE-2008-4577

The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
References
Link Resource
http://bugs.gentoo.org/show_bug.cgi?id=240409 Issue Tracking
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html Mailing List
http://secunia.com/advisories/32164 Broken Link Vendor Advisory
http://secunia.com/advisories/32471 Broken Link
http://secunia.com/advisories/33149 Broken Link
http://secunia.com/advisories/33624 Broken Link
http://secunia.com/advisories/36904 Broken Link
http://security.gentoo.org/glsa/glsa-200812-16.xml Third Party Advisory
http://www.dovecot.org/list/dovecot-news/2008-October/000085.html Mailing List Release Notes
http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 Broken Link
http://www.redhat.com/support/errata/RHSA-2009-0205.html Broken Link
http://www.securityfocus.com/bid/31587 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-838-1 Third Party Advisory
http://www.vupen.com/english/advisories/2008/2745 Permissions Required
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 Broken Link
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html Mailing List
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html Mailing List
http://bugs.gentoo.org/show_bug.cgi?id=240409 Issue Tracking
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html Mailing List
http://secunia.com/advisories/32164 Broken Link Vendor Advisory
http://secunia.com/advisories/32471 Broken Link
http://secunia.com/advisories/33149 Broken Link
http://secunia.com/advisories/33624 Broken Link
http://secunia.com/advisories/36904 Broken Link
http://security.gentoo.org/glsa/glsa-200812-16.xml Third Party Advisory
http://www.dovecot.org/list/dovecot-news/2008-October/000085.html Mailing List Release Notes
http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 Broken Link
http://www.redhat.com/support/errata/RHSA-2009-0205.html Broken Link
http://www.securityfocus.com/bid/31587 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-838-1 Third Party Advisory
http://www.vupen.com/english/advisories/2008/2745 Permissions Required
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 Broken Link
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html Mailing List
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html Mailing List
Configurations

Configuration 1 (hide)

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:opensuse:10.3-11.1:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

History

21 Nov 2024, 00:52

Type Values Removed Values Added
References () http://bugs.gentoo.org/show_bug.cgi?id=240409 - Issue Tracking () http://bugs.gentoo.org/show_bug.cgi?id=240409 - Issue Tracking
References () http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html - Mailing List () http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html - Mailing List
References () http://secunia.com/advisories/32164 - Broken Link, Vendor Advisory () http://secunia.com/advisories/32164 - Broken Link, Vendor Advisory
References () http://secunia.com/advisories/32471 - Broken Link () http://secunia.com/advisories/32471 - Broken Link
References () http://secunia.com/advisories/33149 - Broken Link () http://secunia.com/advisories/33149 - Broken Link
References () http://secunia.com/advisories/33624 - Broken Link () http://secunia.com/advisories/33624 - Broken Link
References () http://secunia.com/advisories/36904 - Broken Link () http://secunia.com/advisories/36904 - Broken Link
References () http://security.gentoo.org/glsa/glsa-200812-16.xml - Third Party Advisory () http://security.gentoo.org/glsa/glsa-200812-16.xml - Third Party Advisory
References () http://www.dovecot.org/list/dovecot-news/2008-October/000085.html - Mailing List, Release Notes () http://www.dovecot.org/list/dovecot-news/2008-October/000085.html - Mailing List, Release Notes
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 - Broken Link () http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 - Broken Link
References () http://www.redhat.com/support/errata/RHSA-2009-0205.html - Broken Link () http://www.redhat.com/support/errata/RHSA-2009-0205.html - Broken Link
References () http://www.securityfocus.com/bid/31587 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/31587 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/USN-838-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-838-1 - Third Party Advisory
References () http://www.vupen.com/english/advisories/2008/2745 - Permissions Required () http://www.vupen.com/english/advisories/2008/2745 - Permissions Required
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 - Broken Link () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 - Broken Link
References () https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html - Mailing List () https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html - Mailing List
References () https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html - Mailing List () https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html - Mailing List

21 Jan 2024, 02:46

Type Values Removed Values Added
CVSS v2 : 6.4
v3 : unknown
v2 : 6.4
v3 : 7.5
CWE CWE-264 CWE-863
References (CONFIRM) http://bugs.gentoo.org/show_bug.cgi?id=240409 - (CONFIRM) http://bugs.gentoo.org/show_bug.cgi?id=240409 - Issue Tracking
References (SECUNIA) http://secunia.com/advisories/36904 - (SECUNIA) http://secunia.com/advisories/36904 - Broken Link
References (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 - (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 - Broken Link
References (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 - (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 - Broken Link
References (BID) http://www.securityfocus.com/bid/31587 - (BID) http://www.securityfocus.com/bid/31587 - Broken Link, Third Party Advisory, VDB Entry
References (SECUNIA) http://secunia.com/advisories/32471 - (SECUNIA) http://secunia.com/advisories/32471 - Broken Link
References (SECUNIA) http://secunia.com/advisories/33149 - (SECUNIA) http://secunia.com/advisories/33149 - Broken Link
References (SECUNIA) http://secunia.com/advisories/33624 - (SECUNIA) http://secunia.com/advisories/33624 - Broken Link
References (VUPEN) http://www.vupen.com/english/advisories/2008/2745 - (VUPEN) http://www.vupen.com/english/advisories/2008/2745 - Permissions Required
References (SECUNIA) http://secunia.com/advisories/32164 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/32164 - Broken Link, Vendor Advisory
References (UBUNTU) http://www.ubuntu.com/usn/USN-838-1 - (UBUNTU) http://www.ubuntu.com/usn/USN-838-1 - Third Party Advisory
References (MLIST) http://www.dovecot.org/list/dovecot-news/2008-October/000085.html - Patch (MLIST) http://www.dovecot.org/list/dovecot-news/2008-October/000085.html - Mailing List, Release Notes
References (FEDORA) https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html - (FEDORA) https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html - Mailing List
References (GENTOO) http://security.gentoo.org/glsa/glsa-200812-16.xml - (GENTOO) http://security.gentoo.org/glsa/glsa-200812-16.xml - Third Party Advisory
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2009-0205.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2009-0205.html - Broken Link
References (FEDORA) https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html - (FEDORA) https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html - Mailing List
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html - Mailing List
First Time Fedoraproject fedora
Canonical ubuntu Linux
Fedoraproject
Canonical
Opensuse opensuse
Opensuse
CPE cpe:2.3:a:dovecot:dovecot:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc22:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc25:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.10:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.beta1:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0_rc29:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.12:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc13:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc23:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc9:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc21:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc17:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc5:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc10:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc20:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.beta8:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.beta3:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc6:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.1:rc2:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc8:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc28:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc2:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.beta9:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc15:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc7:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc19:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc14:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.beta7:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc3:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc18:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc4:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:0.99.14:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc12:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc1:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:0.99.13:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc27:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.beta6:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.beta5:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc24:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc16:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.beta2:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.1:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.beta4:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc11:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.0.rc26:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:10.3-11.1:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

Information

Published : 2008-10-15 20:08

Updated : 2024-11-21 00:52


NVD link : CVE-2008-4577

Mitre link : CVE-2008-4577

CVE.ORG link : CVE-2008-4577


JSON object : View

Products Affected

dovecot

  • dovecot

fedoraproject

  • fedora

canonical

  • ubuntu_linux

opensuse

  • opensuse
CWE
CWE-863

Incorrect Authorization