Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dovecot | Jul 30, 2024 | Mar 6, 2008 |
| Gentoo Linux | — | Upgrade net-mail/dovecot. | Oct 30, 2017 | Mar 6, 2008 |
| Oracle_linux | — | Upgrade dovecot | Oct 16, 2024 | Mar 6, 2008 |
| Suse | — | Upgrade suse-releaseUpgrade dovecot-develUpgrade dovecot | Feb 17, 2015 | Mar 6, 2008 |
| Ubuntu | — | Upgrade dovecot-imapdUpgrade dovecot-pop3dUpgrade dovecot-common | Nov 8, 2024 | Mar 6, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub