Back to search
CVE-2008-4578
Published: Oct 15, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
32164
third-party-advisory
x_refsource_SECUNIA
dovecot-acl-mailbox-security-bypass(45669)
vdb-entry
x_refsource_XF
33149
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2745
vdb-entry
x_refsource_VUPEN
31587
vdb-entry
x_refsource_BID
MDVSA-2008:232
vendor-advisory
x_refsource_MANDRIVA
GLSA-200812-16
vendor-advisory
x_refsource_GENTOO
http://bugs.gentoo.org/show_bug.cgi?id=240409
x_refsource_CONFIRM
[Dovecot-news] 20081005 v1.1.4 released
mailing-list
x_refsource_MLIST
20081119 Re: [ MDVSA-2008:232 ] dovecot
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now