CVE-2009-3897
 
Severity Score
5.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
Dovecot v1.2.x anterior v1.2.8 establece permisos 0777 durante la creación de ciertos directorios en el momento de la instalación, permitiendo a usuarios locales acceder a las cuentas de usuarios por reemplazamiento del socket auth, relacionados con los directorios padre del directorio base_dir, y probablemente con el propio directorio base_dir
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-11-05 CVE Reserved
- 2009-11-24 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=oss-security&m=125881481222441&w=2 | Mailing List | |
http://marc.info/?l=oss-security&m=125900271508796&w=2 | Mailing List | |
http://www.osvdb.org/60316 | Broken Link | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/54363 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://marc.info/?l=oss-security&m=125871729029145&w=2 | 2024-02-08 | |
http://marc.info/?l=oss-security&m=125900267208712&w=2 | 2024-02-08 | |
http://www.dovecot.org/list/dovecot-news/2009-November/000143.html | 2024-02-08 | |
http://www.securityfocus.com/bid/37084 | 2024-02-08 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html | 2024-02-08 | |
http://secunia.com/advisories/37443 | 2024-02-08 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2009:306 | 2024-02-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dovecot Search vendor "Dovecot" | Dovecot Search vendor "Dovecot" for product "Dovecot" | >= 1.2.0 < 1.2.8 Search vendor "Dovecot" for product "Dovecot" and version " >= 1.2.0 < 1.2.8" | - |
Affected
|