CVE-2008-4578
Mandriva Linux Security Advisory 2008-232
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
El plugin ACL en Dovecot anterior a 1.1.4 permite a atacantes remotos evitar las restricciones de acceso previstas utilizando la "k" derecha para crear buzones de correo "parent/child/child" no autorizados.
The ACL plugin in dovecot prior to version 1.1.4 treated negative access rights as though they were positive access rights, which allowed attackers to bypass intended access restrictions. The ACL plugin in dovecot prior to version 1.1.6 allowed attackers to bypass intended access restrictions by using the 'k' right to create unauthorized 'parent/child/child' mailboxes.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-10-15 CVE Reserved
- 2008-10-15 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://bugs.gentoo.org/show_bug.cgi?id=240409 | X_refsource_confirm | |
http://secunia.com/advisories/33149 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/498498/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/31587 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2745 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45669 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.dovecot.org/list/dovecot-news/2008-October/000085.html | 2018-10-11 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/32164 | 2018-10-11 | |
http://security.gentoo.org/glsa/glsa-200812-16.xml | 2018-10-11 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | <= 1.1.3 Search vendor "Dovecot" for product "Dovecot" and version " <= 1.1.3" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 0.99.13 Search vendor "Dovecot" for product "Dovecot" and version "0.99.13" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 0.99.14 Search vendor "Dovecot" for product "Dovecot" and version "0.99.14" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0 Search vendor "Dovecot" for product "Dovecot" and version "1.0" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.2 Search vendor "Dovecot" for product "Dovecot" and version "1.0.2" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.3 Search vendor "Dovecot" for product "Dovecot" and version "1.0.3" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.4 Search vendor "Dovecot" for product "Dovecot" and version "1.0.4" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.5 Search vendor "Dovecot" for product "Dovecot" and version "1.0.5" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.6 Search vendor "Dovecot" for product "Dovecot" and version "1.0.6" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.7 Search vendor "Dovecot" for product "Dovecot" and version "1.0.7" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.8 Search vendor "Dovecot" for product "Dovecot" and version "1.0.8" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.9 Search vendor "Dovecot" for product "Dovecot" and version "1.0.9" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.10 Search vendor "Dovecot" for product "Dovecot" and version "1.0.10" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.12 Search vendor "Dovecot" for product "Dovecot" and version "1.0.12" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.beta1 Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta1" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.beta2 Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta2" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.beta3 Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta3" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.beta4 Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta4" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.beta5 Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta5" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.beta6 Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta6" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.beta7 Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta7" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.beta8 Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta8" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.beta9 Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta9" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc1 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc1" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc2 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc2" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc3 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc3" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc4 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc4" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc5 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc5" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc6 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc6" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc7 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc7" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc8 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc8" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc9 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc9" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc10 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc10" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc11 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc11" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc12 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc12" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc13 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc13" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc14 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc14" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc15 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc15" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc16 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc16" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc17 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc17" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc18 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc18" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc19 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc19" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc20 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc20" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc21 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc21" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc22 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc22" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc23 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc23" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc24 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc24" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc25 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc25" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc26 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc26" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc27 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc27" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0.rc28 Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc28" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.0_rc29 Search vendor "Dovecot" for product "Dovecot" and version "1.0_rc29" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.1 Search vendor "Dovecot" for product "Dovecot" and version "1.1" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.1 Search vendor "Dovecot" for product "Dovecot" and version "1.1" | rc2 |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.1.0 Search vendor "Dovecot" for product "Dovecot" and version "1.1.0" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.1.1 Search vendor "Dovecot" for product "Dovecot" and version "1.1.1" | - |
Affected
| ||||||
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | 1.1.2 Search vendor "Dovecot" for product "Dovecot" and version "1.1.2" | - |
Affected
|