CVE-2008-1199

Dovecot - Symlink Attack via mail_extra_groups Configuration

Title source: llm
STIX 2.1

Description

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

References (18)

Core 18
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200803-25.xml
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10739
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29557
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/489133/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30342
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0297.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1516
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/593-1/
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28092
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29226
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32151
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29385
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41009
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29396

Scores

EPSS 0.0034
EPSS Percentile 25.9%

Details

CWE
CWE-16 CWE-59
Status published
Products (32)
dovecot/dovecot 0.99.13
dovecot/dovecot 0.99.14
dovecot/dovecot 1.0
dovecot/dovecot 1.0.2
dovecot/dovecot 1.0.3
dovecot/dovecot 1.0.4
dovecot/dovecot 1.0.5
dovecot/dovecot 1.0.6
dovecot/dovecot 1.0.7
dovecot/dovecot 1.0.8
... and 22 more
Published Mar 06, 2008
Tracked Since Feb 18, 2026