5
CVSSv2

CVE-2008-4578

Published: 15/10/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The ACL plugin in Dovecot prior to 1.1.4 allows malicious users to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot 1.0.rc15

dovecot dovecot 1.0.rc14

dovecot dovecot 1.0.7

dovecot dovecot 1.0.rc22

dovecot dovecot 1.0.9

dovecot dovecot 1.0.rc25

dovecot dovecot 0.99.13

dovecot dovecot 1.0.beta2

dovecot dovecot 1.0.5

dovecot dovecot 1.0.beta6

dovecot dovecot 1.0.rc13

dovecot dovecot 1.0.rc5

dovecot dovecot 1.1.0

dovecot dovecot 1.1.1

dovecot dovecot 1.0.12

dovecot dovecot 1.1

dovecot dovecot 1.0.rc20

dovecot dovecot 1.0.rc2

dovecot dovecot 1.0.8

dovecot dovecot 1.0.rc23

dovecot dovecot 1.0.rc26

dovecot dovecot 1.0.beta1

dovecot dovecot 1.0_rc29

dovecot dovecot 1.0.4

dovecot dovecot 1.0.beta5

dovecot dovecot 1.0.rc11

dovecot dovecot 1.0.rc12

dovecot dovecot 1.0.rc7

dovecot dovecot 1.0.rc8

dovecot dovecot 1.0.rc19

dovecot dovecot 1.0.rc18

dovecot dovecot 1.0.10

dovecot dovecot 1.0.rc24

dovecot dovecot 1.0

dovecot dovecot 1.0.2

dovecot dovecot 1.0.3

dovecot dovecot 1.0.beta4

dovecot dovecot 1.0.beta9

dovecot dovecot 1.0.rc1

dovecot dovecot 1.0.rc10

dovecot dovecot 1.0.rc4

dovecot dovecot 1.0.rc9

dovecot dovecot 1.0.rc17

dovecot dovecot 1.0.rc16

dovecot dovecot 1.0.6

dovecot dovecot 1.0.rc21

dovecot dovecot 1.0.rc28

dovecot dovecot 1.0.rc27

dovecot dovecot 0.99.14

dovecot dovecot 1.0.beta3

dovecot dovecot 1.0.beta7

dovecot dovecot 1.0.beta8

dovecot dovecot 1.0.rc6

dovecot dovecot 1.0.rc3

dovecot dovecot 1.1.2

dovecot dovecot

Vendor Advisories

Debian Bug report logs - #502967 CVE-2008-4577/CVE-2008-4578: security problems with the ACL plugin Package: dovecot-common; Maintainer for dovecot-common is (unknown); Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Tue, 21 Oct 2008 11:30:02 UTC Severity: important Tags: security Fixed in version 1:119 ...