Back

MEDIUM

dovecot: insecure mail_extra_groups option

Published Mar 6, 2008

Description

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

Affected products

Remediation

Red Hat statement

This issue does not affect the default configuration of Dovecot as shipped in Red Hat Enterprise Linux.

Metrics

Weaknesses (2)

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 6, 2008
Updated Aug 7, 2024
Reserved Mar 6, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Mar 4, 2008