CVE-2008-1199Link Following in Dovecot

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 89.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 6
Latest updateMay 1

Description

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

CVSS vector

AV:L/AC:M/C:P/I:P/A:PExploitability: 3.4 | Impact: 6.4

Affected Packages3 packages

debiandebian/dovecot< dovecot 1:1.0.12-1 (bookworm)
Debiandovecot/dovecot< 1:1.0.12-1+3
NVDdovecot/dovecot32 versions+31

Patches

🔴Vulnerability Details

2
GHSA
GHSA-778f-c3r9-6vmp: Dovecot before 12022-05-01
OSV
CVE-2008-1199: Dovecot before 12008-03-06

📋Vendor Advisories

3
Ubuntu
Dovecot vulnerabilities2008-03-26
Red Hat
dovecot: insecure mail_extra_groups option2008-03-04
Debian
CVE-2008-1199: dovecot - Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot...2008

💬Community

1
Bugzilla
CVE-2008-1199 dovecot: insecure mail_extra_groups option2008-03-11