LWN.net Logo

dovecot: multiple vulnerabilities

Package(s):dovecot CVE #(s):CVE-2008-1199 CVE-2008-1218
Created:March 13, 2008 Updated:October 7, 2008
Description: From the Fedora alert:

CVE-2008-1199 If Dovecot was configured with mail_extra_groups = mail, users having shell access to IMAP server could use this flaw to read, modify or delete mails of other users stored in inbox files in /var/mail. /var/mail directory is mail-group writable and user inbox files are by default created by useradd with permission 660, <user>:mail. No mail_extra_groups is set by default, hence default Fedora configuration was not affected by this problem. If your configuration sets mail_extra_groups, see new options mail_privileged_group and mail_access_groups introduced in Dovecot 1.0.11. (mail_extra_groups is still accepted, but is deprecated now)

CVE-2008-1218 On Dovecot versions 1.0.11 and newer, it was possible to gain password-less login via passwords with tab characters, which were not filtered properly. Dovecot versions in Fedora were not affected by this unauthorized login flaw, but only by a related minor memory leak in dovecot-auth worker process.

Alerts:
SuSE SUSE-SR:2008:020 2008-10-07
Red Hat RHSA-2008:0297-02 2008-05-21
Ubuntu USN-593-1 2008-03-26
Gentoo 200803-25 2008-03-18
Debian DSA-1516-1 2008-03-14
Fedora FEDORA-2008-2464 2008-03-13
rPath rPSA-2008-0108-1 2008-03-12
Fedora FEDORA-2008-2475 2008-03-13

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds