CVE-2009-3897

Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*

History

08 Feb 2024, 15:21

Type Values Removed Values Added
CWE CWE-264 CWE-732
CPE cpe:2.3:a:dovecot:dovecot:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
References () http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html - () http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html - Mailing List
References () http://marc.info/?l=oss-security&m=125871729029145&w=2 - Patch () http://marc.info/?l=oss-security&m=125871729029145&w=2 - Mailing List, Patch
References () http://marc.info/?l=oss-security&m=125881481222441&w=2 - () http://marc.info/?l=oss-security&m=125881481222441&w=2 - Mailing List
References () http://marc.info/?l=oss-security&m=125900267208712&w=2 - Patch () http://marc.info/?l=oss-security&m=125900267208712&w=2 - Mailing List, Patch
References () http://marc.info/?l=oss-security&m=125900271508796&w=2 - () http://marc.info/?l=oss-security&m=125900271508796&w=2 - Mailing List
References () http://secunia.com/advisories/37443 - Vendor Advisory () http://secunia.com/advisories/37443 - Broken Link, Vendor Advisory
References () http://www.dovecot.org/list/dovecot-news/2009-November/000143.html - Patch, Vendor Advisory () http://www.dovecot.org/list/dovecot-news/2009-November/000143.html - Mailing List, Patch, Vendor Advisory
References () http://www.mandriva.com/security/advisories?name=MDVSA-2009:306 - () http://www.mandriva.com/security/advisories?name=MDVSA-2009:306 - Not Applicable
References () http://www.osvdb.org/60316 - () http://www.osvdb.org/60316 - Broken Link
References () http://www.securityfocus.com/bid/37084 - Patch () http://www.securityfocus.com/bid/37084 - Broken Link, Patch, Third Party Advisory, VDB Entry
References () http://www.vupen.com/english/advisories/2009/3306 - Patch, Vendor Advisory () http://www.vupen.com/english/advisories/2009/3306 - Patch, Permissions Required, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/54363 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/54363 - Third Party Advisory, VDB Entry
CVSS v2 : 4.6
v3 : unknown
v2 : 4.6
v3 : 5.5

Information

Published : 2009-11-24 17:30

Updated : 2024-02-08 15:21


NVD link : CVE-2009-3897

Mitre link : CVE-2009-3897

CVE.ORG link : CVE-2009-3897


JSON object : View

Products Affected

dovecot

  • dovecot
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource