LWN.net Logo

dovecot: negative rights in ACL plugin

Package(s):dovecot CVE #(s):CVE-2008-4577
Created:October 30, 2008 Updated:September 28, 2009
Description: dovecot has a restriction bypass vulnerability. From the vulnerability database entry:

The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.

Alerts:
Ubuntu USN-838-1 2009-09-28
SuSE SUSE-SR:2009:004 2009-02-17
rPath rPSA-2008-0341-1 2008-12-22
Red Hat RHSA-2009:0205-02 2009-01-20
Gentoo 200812-16 2008-12-14
Mandriva MDVSA-2008:232 2008-11-19
Fedora FEDORA-2008-9202 2008-10-30
Fedora FEDORA-2008-9232 2008-10-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds