CVE-2009-3897
published 2009-11-24CVE-2009-3897: Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.38%
30.1th percentile
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:1.2.8-1 (bookworm) | dovecot 1:1.2.8-1 (bookworm) |
| dovecot | dovecot | >= 0 < 1:1.2.8-1 | 1:1.2.8-1 |
| dovecot | dovecot | >= 0 < 1:1.2.8-1 | 1:1.2.8-1 |
| dovecot | dovecot | >= 0 < 1:1.2.8-1 | 1:1.2.8-1 |
| dovecot | dovecot | >= 0 < 1:1.2.8-1 | 1:1.2.8-1 |
| dovecot | dovecot | >= 1.2.0 < 1.2.8 | 1.2.8 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-89r5-2fhc-hwj7: Dovecot 1
ghsa_unreviewed·2022-05-02
CVE-2009-3897 [MEDIUM] CWE-732 GHSA-89r5-2fhc-hwj7: Dovecot 1
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
OSV
CVE-2009-3897: Dovecot 1
osv·2009-11-24·CVSS 5.5
CVE-2009-3897 [MEDIUM] CVE-2009-3897: Dovecot 1
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
Red Hat
dovecot: Insecure permissions set for certain directories at installation time
vendor_redhat·2009-11-20·CVSS 5.5
CVE-2009-3897 [MEDIUM] CWE-732 dovecot: Insecure permissions set for certain directories at installation time
dovecot: Insecure permissions set for certain directories at installation time
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
Statement: This issue did not affect the version of dovecot shipped with Red Hat Enterprise Linux 6.
Package: dovecot (Red Hat Enterprise Linux 4) - Not affected
Package: dovecot (Red Hat Enterprise Linux 5) - Will not fix
Package: dovecot (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2009-3897: dovecot - Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain dire...
vendor_debian·2009·CVSS 5.5
CVE-2009-3897 [MEDIUM] CVE-2009-3897: dovecot - Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain dire...
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
Scope: local
bookworm: resolved (fixed in 1:1.2.8-1)
bullseye: resolved (fixed in 1:1.2.8-1)
forky: resolved (fixed in 1:1.2.8-1)
sid: resolved (fixed in 1:1.2.8-1)
trixie: resolved (fixed in 1:1.2.8-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.htmlhttp://marc.info/?l=oss-security&m=125871729029145&w=2http://marc.info/?l=oss-security&m=125881481222441&w=2http://marc.info/?l=oss-security&m=125900267208712&w=2http://marc.info/?l=oss-security&m=125900271508796&w=2http://secunia.com/advisories/37443http://www.dovecot.org/list/dovecot-news/2009-November/000143.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:306http://www.osvdb.org/60316http://www.securityfocus.com/bid/37084http://www.vupen.com/english/advisories/2009/3306https://exchange.xforce.ibmcloud.com/vulnerabilities/54363http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.htmlhttp://marc.info/?l=oss-security&m=125871729029145&w=2http://marc.info/?l=oss-security&m=125881481222441&w=2http://marc.info/?l=oss-security&m=125900267208712&w=2http://marc.info/?l=oss-security&m=125900271508796&w=2http://secunia.com/advisories/37443http://www.dovecot.org/list/dovecot-news/2009-November/000143.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:306http://www.osvdb.org/60316http://www.securityfocus.com/bid/37084http://www.vupen.com/english/advisories/2009/3306https://exchange.xforce.ibmcloud.com/vulnerabilities/54363
2009-11-24
Published