CVE-2008-5301
published 2008-12-01CVE-2008-5301: Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve…
PriorityP432medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.83%
76.6th percentile
Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:1.0.15-2.3 (bookworm) | dovecot 1:1.0.15-2.3 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | >= 0 < 1:1.0.15-2.3 | 1:1.0.15-2.3 |
| dovecot | dovecot | >= 0 < 1:1.0.15-2.3 | 1:1.0.15-2.3 |
| dovecot | dovecot | >= 0 < 1:1.0.15-2.3 | 1:1.0.15-2.3 |
| dovecot | dovecot | >= 0 < 1:1.0.15-2.3 | 1:1.0.15-2.3 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gp93-h8f7-238h: Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1
ghsa_unreviewed·2022-05-17
CVE-2008-5301 [MEDIUM] CWE-22 GHSA-gp93-h8f7-238h: Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1
Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
OSV
CVE-2008-5301: Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1
osv·2008-12-01·CVSS 6.4
CVE-2008-5301 [MEDIUM] CVE-2008-5301: Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1
Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2009-09-28·CVSS 7.5
CVE-2008-4577 [HIGH] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Dovecot vulnerabilities
It was discovered that the ACL plugin in Dovecot would incorrectly handle
negative access rights. An attacker could exploit this flaw to access the
Dovecot server, bypassing the intended access restrictions. This only
affected Ubuntu 8.04 LTS. (CVE-2008-4577)
It was discovered that the ManageSieve service in Dovecot incorrectly
handled ".." in script names. A remote attacker could exploit this to read
and modify arbitrary sieve files on the server. This only affected Ubuntu
8.10. (CVE-2008-5301)
It was discovered that the Sieve plugin in Dovecot incorrectly handled
certain sieve scripts. An authenticated user could exploit this with a
crafted sieve script to cause a denial of service or possibly execute
arbitrary code. (CV
Debian
CVE-2008-5301: dovecot - Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1...
vendor_debian·2008·CVSS 6.4
CVE-2008-5301 [MEDIUM] CVE-2008-5301: dovecot - Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1...
Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
Scope: local
bookworm: resolved (fixed in 1:1.0.15-2.3)
bullseye: resolved (fixed in 1:1.0.15-2.3)
forky: resolved (fixed in 1:1.0.15-2.3)
sid: resolved (fixed in 1:1.0.15-2.3)
trixie: resolved (fixed in 1:1.0.15-2.3)
Red Hat
CVE-2008-5301: Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1
vendor_redhat·CVSS 6.4
CVE-2008-5301 [MEDIUM] CVE-2008-5301: Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1
Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
Statement: Not vulnerable. This issue did not affect the versions of dovecot as shipped with Red Hat Enterprise Linux 4, or 5. Those packages do not include ManageSieve server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/32768http://secunia.com/advisories/36904http://www.dovecot.org/list/dovecot/2008-November/035259.htmlhttp://www.securityfocus.com/bid/32582http://www.ubuntu.com/usn/USN-838-1http://www.vupen.com/english/advisories/2008/3190https://exchange.xforce.ibmcloud.com/vulnerabilities/46672http://secunia.com/advisories/32768http://secunia.com/advisories/36904http://www.dovecot.org/list/dovecot/2008-November/035259.htmlhttp://www.securityfocus.com/bid/32582http://www.ubuntu.com/usn/USN-838-1http://www.vupen.com/english/advisories/2008/3190https://exchange.xforce.ibmcloud.com/vulnerabilities/46672
2008-12-01
Published