|
|
| |
|
| |
dovecot: arbitrary file modification
| Package(s): | dovecot |
CVE #(s): | CVE-2008-5301
|
| Created: | September 28, 2009 |
Updated: | September 30, 2009 |
| Description: |
From the Ubuntu advisory:
It was discovered that the ManageSieve service in Dovecot incorrectly
handled ".." in script names. A remote attacker could exploit this to read
and modify arbitrary sieve files on the server. This only affected Ubuntu
8.10. (CVE-2008-5301)
|
| Alerts: |
|
( Log in to post comments)
|
|
|