LWN.net Logo

dovecot: arbitrary file modification

Package(s):dovecot CVE #(s):CVE-2008-5301
Created:September 28, 2009 Updated:September 30, 2009
Description:

From the Ubuntu advisory:

It was discovered that the ManageSieve service in Dovecot incorrectly handled ".." in script names. A remote attacker could exploit this to read and modify arbitrary sieve files on the server. This only affected Ubuntu 8.10. (CVE-2008-5301)

Alerts:
Ubuntu USN-838-1 2009-09-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds