CVE-2009-3897

Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html Mailing List
http://marc.info/?l=oss-security&m=125871729029145&w=2 Mailing List Patch
http://marc.info/?l=oss-security&m=125881481222441&w=2 Mailing List
http://marc.info/?l=oss-security&m=125900267208712&w=2 Mailing List Patch
http://marc.info/?l=oss-security&m=125900271508796&w=2 Mailing List
http://secunia.com/advisories/37443 Broken Link Vendor Advisory
http://www.dovecot.org/list/dovecot-news/2009-November/000143.html Mailing List Patch Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:306 Not Applicable
http://www.osvdb.org/60316 Broken Link
http://www.securityfocus.com/bid/37084 Broken Link Patch Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2009/3306 Patch Permissions Required Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/54363 Third Party Advisory VDB Entry
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html Mailing List
http://marc.info/?l=oss-security&m=125871729029145&w=2 Mailing List Patch
http://marc.info/?l=oss-security&m=125881481222441&w=2 Mailing List
http://marc.info/?l=oss-security&m=125900267208712&w=2 Mailing List Patch
http://marc.info/?l=oss-security&m=125900271508796&w=2 Mailing List
http://secunia.com/advisories/37443 Broken Link Vendor Advisory
http://www.dovecot.org/list/dovecot-news/2009-November/000143.html Mailing List Patch Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:306 Not Applicable
http://www.osvdb.org/60316 Broken Link
http://www.securityfocus.com/bid/37084 Broken Link Patch Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2009/3306 Patch Permissions Required Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/54363 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-11-24 17:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-3897

Mitre link : CVE-2009-3897

CVE.ORG link : CVE-2009-3897


JSON object : View

Products Affected

dovecot

  • dovecot
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource