CVE-2008-1199
published 2008-03-06CVE-2008-1199: Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive…
PriorityP410medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.34%
26.6th percentile
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:1.0.12-1 (bookworm) | dovecot 1:1.0.12-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2008-03-26·CVSS 4.4
CVE-2008-1218 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Dovecot vulnerabilities
It was discovered that the default configuration of dovecot could allow
access to any email files with group "mail" without verifying that a user
had valid rights. An attacker able to create symlinks in their mail
directory could exploit this to read or delete another user's email.
(CVE-2008-1199)
By default, dovecot passed special characters to the underlying
authentication systems. While Ubuntu releases of dovecot are not known
to be vulnerable, the authentication routine was proactively improved
to avoid potential future problems. (CVE-2008-1218)
Instructions: After a standard system upgrade, additional dovecot configuration changes
are needed.
ATTENTION: Due to an unavoidable configuration update, the dovecot
settings
Red Hat
dovecot: insecure mail_extra_groups option
vendor_redhat·2008-03-04·CVSS 4.4
CVE-2008-1199 [MEDIUM] dovecot: insecure mail_extra_groups option
dovecot: insecure mail_extra_groups option
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
Statement: This issue does not affect the default configuration of Dovecot as shipped in Red Hat Enterprise Linux.
Debian
CVE-2008-1199: dovecot - Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot...
vendor_debian·2008·CVSS 4.4
CVE-2008-1199 [MEDIUM] CVE-2008-1199: dovecot - Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot...
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
Scope: local
bookworm: resolved (fixed in 1:1.0.12-1)
bullseye: resolved (fixed in 1:1.0.12-1)
forky: resolved (fixed in 1:1.0.12-1)
sid: resolved (fixed in 1:1.0.12-1)
trixie: resolved (fixed in 1:1.0.12-1)
GHSA
GHSA-778f-c3r9-6vmp: Dovecot before 1
ghsa_unreviewed·2022-05-01
CVE-2008-1199 [MEDIUM] GHSA-778f-c3r9-6vmp: Dovecot before 1
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
OSV
CVE-2008-1199: Dovecot before 1
osv·2008-03-06·CVSS 4.4
CVE-2008-1199 [MEDIUM] CVE-2008-1199: Dovecot before 1
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00004.htmlhttp://secunia.com/advisories/29226http://secunia.com/advisories/29385http://secunia.com/advisories/29396http://secunia.com/advisories/29557http://secunia.com/advisories/30342http://secunia.com/advisories/32151http://security.gentoo.org/glsa/glsa-200803-25.xmlhttp://www.debian.org/security/2008/dsa-1516http://www.dovecot.org/list/dovecot-news/2008-March/000061.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0297.htmlhttp://www.securityfocus.com/archive/1/489133/100/0/threadedhttp://www.securityfocus.com/bid/28092https://exchange.xforce.ibmcloud.com/vulnerabilities/41009https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10739https://usn.ubuntu.com/593-1/https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00358.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00381.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00004.htmlhttp://secunia.com/advisories/29226http://secunia.com/advisories/29385http://secunia.com/advisories/29396http://secunia.com/advisories/29557http://secunia.com/advisories/30342http://secunia.com/advisories/32151http://security.gentoo.org/glsa/glsa-200803-25.xmlhttp://www.debian.org/security/2008/dsa-1516http://www.dovecot.org/list/dovecot-news/2008-March/000061.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0297.htmlhttp://www.securityfocus.com/archive/1/489133/100/0/threadedhttp://www.securityfocus.com/bid/28092https://exchange.xforce.ibmcloud.com/vulnerabilities/41009https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10739https://usn.ubuntu.com/593-1/https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00358.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00381.html
2008-03-06
Published