CVE-2008-4577

The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
References
Link Resource
http://bugs.gentoo.org/show_bug.cgi?id=240409 Issue Tracking
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html Mailing List
http://secunia.com/advisories/32164 Broken Link Vendor Advisory
http://secunia.com/advisories/32471 Broken Link
http://secunia.com/advisories/33149 Broken Link
http://secunia.com/advisories/33624 Broken Link
http://secunia.com/advisories/36904 Broken Link
http://security.gentoo.org/glsa/glsa-200812-16.xml Third Party Advisory
http://www.dovecot.org/list/dovecot-news/2008-October/000085.html Mailing List Release Notes
http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 Broken Link
http://www.redhat.com/support/errata/RHSA-2009-0205.html Broken Link
http://www.securityfocus.com/bid/31587 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-838-1 Third Party Advisory
http://www.vupen.com/english/advisories/2008/2745 Permissions Required
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 Broken Link
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html Mailing List
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html Mailing List
http://bugs.gentoo.org/show_bug.cgi?id=240409 Issue Tracking
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html Mailing List
http://secunia.com/advisories/32164 Broken Link Vendor Advisory
http://secunia.com/advisories/32471 Broken Link
http://secunia.com/advisories/33149 Broken Link
http://secunia.com/advisories/33624 Broken Link
http://secunia.com/advisories/36904 Broken Link
http://security.gentoo.org/glsa/glsa-200812-16.xml Third Party Advisory
http://www.dovecot.org/list/dovecot-news/2008-October/000085.html Mailing List Release Notes
http://www.mandriva.com/security/advisories?name=MDVSA-2008:232 Broken Link
http://www.redhat.com/support/errata/RHSA-2009-0205.html Broken Link
http://www.securityfocus.com/bid/31587 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-838-1 Third Party Advisory
http://www.vupen.com/english/advisories/2008/2745 Permissions Required
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376 Broken Link
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html Mailing List
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html Mailing List
Configurations

Configuration 1 (hide)

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:opensuse:10.3-11.1:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-10-15 20:08

Updated : 2025-04-09 00:30


NVD link : CVE-2008-4577

Mitre link : CVE-2008-4577

CVE.ORG link : CVE-2008-4577


JSON object : View

Products Affected

fedoraproject

  • fedora

canonical

  • ubuntu_linux

opensuse

  • opensuse

dovecot

  • dovecot
CWE
CWE-863

Incorrect Authorization