CVE-2008-1199

Source
https://nvd.nist.gov/vuln/detail/CVE-2008-1199
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2008-1199.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2008-1199
Related
Published
2008-03-06T21:44:00Z
Modified
2024-06-30T12:01:22Z
Summary
[none]
Details

Dovecot before 1.0.11, when configured to use mailextragroups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

References

Affected packages

Debian:11 / dovecot

Package

Name
dovecot
Purl
pkg:deb/debian/dovecot?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.0.12-1

Ecosystem specific

{
    "urgency": "medium"
}

Debian:12 / dovecot

Package

Name
dovecot
Purl
pkg:deb/debian/dovecot?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.0.12-1

Ecosystem specific

{
    "urgency": "medium"
}

Debian:13 / dovecot

Package

Name
dovecot
Purl
pkg:deb/debian/dovecot?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.0.12-1

Ecosystem specific

{
    "urgency": "medium"
}