Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dovecot | Jul 30, 2024 | Nov 24, 2009 |
| Freebsd | — | Upgrade dovecot | Dec 10, 2025 | Dec 10, 2009 |
| Gentoo Linux | — | Upgrade net-mail/dovecot. | Oct 30, 2017 | Nov 24, 2009 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 20, 2009 |
| Suse | — | Upgrade dovecot12-develUpgrade dovecot12-backend-pgsqlUpgrade dovecot12-backend-sqliteUpgrade dovecot12-fts-luceneUpgrade dovecot12-backend-mysqlUpgrade dovecot12 | Feb 17, 2015 | Nov 24, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub