MEDIUM
dovecot: bypass of the 'k' right in the ACL plugin
Published Oct 15, 2008
5.0
MEDIUMCVSS 2.0
EPSS 1.68%
Description
The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
Affected products
No data.
OR
- ≤ 1.1.3
- 0.99.13
- 0.99.14
- 1.0
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.0.9
- 1.0.10
- 1.0.12
- 1.0.beta1
- 1.0.beta2
- 1.0.beta3
- 1.0.beta4
- 1.0.beta5
- 1.0.beta6
- 1.0.beta7
- 1.0.beta8
- 1.0.beta9
- 1.0.rc1
- 1.0.rc2
- 1.0.rc3
- 1.0.rc4
- 1.0.rc5
- 1.0.rc6
- 1.0.rc7
- 1.0.rc8
- 1.0.rc9
- 1.0.rc10
- 1.0.rc11
- 1.0.rc12
- 1.0.rc13
- 1.0.rc14
- 1.0.rc15
- 1.0.rc16
- 1.0.rc17
- 1.0.rc18
- 1.0.rc19
- 1.0.rc20
- 1.0.rc21
- 1.0.rc22
- 1.0.rc23
- 1.0.rc24
- 1.0.rc25
- 1.0.rc26
- 1.0.rc27
- 1.0.rc28
- 1.0_rc29
- 1.1
- 1.1
- 1.1.0
- 1.1.1
- 1.1.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 5.
Weaknesses (1)
References (14)
- http://bugs.gentoo.org/show_bug.cgi?id=240409 x_refsource_CONFIRM
- http://secunia.com/advisories/32164 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/33149 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200812-16.xml vendor-advisoryx_refsource_GENTOO
- http://www.dovecot.org/list/dovecot-news/2008-October/000085.html mailing-listx_refsource_MLISTPatch
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/archive/1/498498/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/31587 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2008/2745 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-4578 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=467437 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45669 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-4578
- https://www.cve.org/CVERecord?id=CVE-2008-4578
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 15, 2008
Updated Aug 7, 2024
Reserved Oct 15, 2008
Link CVE-2008-4578
CISA Vulnrichment
Updated n/a