Vulnerability Description
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dovecot | Dovecot | < 1.1.4 |
| Fedoraproject | Fedora | 8 |
| Opensuse | Opensuse | 10.3-11.1 |
| Canonical | Ubuntu Linux | 8.04 |
Related Weaknesses (CWE)
References
- http://bugs.gentoo.org/show_bug.cgi?id=240409Issue Tracking
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlMailing List
- http://secunia.com/advisories/32164Broken LinkVendor Advisory
- http://secunia.com/advisories/32471Broken Link
- http://secunia.com/advisories/33149Broken Link
- http://secunia.com/advisories/33624Broken Link
- http://secunia.com/advisories/36904Broken Link
- http://security.gentoo.org/glsa/glsa-200812-16.xmlThird Party Advisory
- http://www.dovecot.org/list/dovecot-news/2008-October/000085.htmlMailing ListRelease Notes
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:232Broken Link
- http://www.redhat.com/support/errata/RHSA-2009-0205.htmlBroken Link
- http://www.securityfocus.com/bid/31587Broken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-838-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/2745Permissions Required
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Broken Link
FAQ
What is CVE-2008-4577?
CVE-2008-4577 is a vulnerability with a CVSS score of 7.5 (HIGH). The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
How severe is CVE-2008-4577?
CVE-2008-4577 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4577?
Check the references section above for vendor advisories and patch information. Affected products include: Dovecot Dovecot, Fedoraproject Fedora, Opensuse Opensuse, Canonical Ubuntu Linux.