Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2008-1199

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

  • Published: Mar 6, 2008
  • Updated: Apr 13, 2023
  • CVE: CVE-2008-1199
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.4
  • AV:L/AC:M/Au:N/C:P/I:P/A:P
Software From Fixed in
dovecot / dovecot 1.0.6 1.0.6.x
dovecot / dovecot 1.0.beta2 1.0.beta2.x
dovecot / dovecot 1.0.5 1.0.5.x
dovecot / dovecot 1.0 1.0.x
dovecot / dovecot 1.0.rc15 1.0.rc15.x
dovecot / dovecot 1.0.rc12 1.0.rc12.x
dovecot / dovecot 1.0.rc14 1.0.rc14.x
dovecot / dovecot 1.0.2 1.0.2.x
dovecot / dovecot 1.0.rc8 1.0.rc8.x
dovecot / dovecot 1.0.rc2 1.0.rc2.x
dovecot / dovecot 1.0.7 1.0.7.x
dovecot / dovecot 0.99.14 0.99.14.x
dovecot / dovecot 1.0.beta8 1.0.beta8.x
dovecot / dovecot 1.0.beta3 1.0.beta3.x
dovecot / dovecot 1.0.3 1.0.3.x
dovecot / dovecot 1.0.rc9 1.0.rc9.x
dovecot / dovecot 1.0.rc13 1.0.rc13.x
dovecot / dovecot 1.0.8 1.0.8.x
dovecot / dovecot 1.0.rc11 1.0.rc11.x
dovecot / dovecot 1.0.4 1.0.4.x
dovecot / dovecot 1.0.rc6 1.0.rc6.x
dovecot / dovecot 1.0.rc3 1.0.rc3.x
dovecot / dovecot 1.0.10 1.0.10.x
dovecot / dovecot 1.0.9 1.0.9.x
dovecot / dovecot 1.0.rc1 1.0.rc1.x
dovecot / dovecot 0.99.13 0.99.13.x
dovecot / dovecot 1.0.rc10 1.0.rc10.x
dovecot / dovecot 1.0_rc29 1.0_rc29.x
dovecot / dovecot 1.0.rc7 1.0.rc7.x
dovecot / dovecot 1.0.rc5 1.0.rc5.x
dovecot / dovecot 1.0.beta7 1.0.beta7.x
dovecot / dovecot 1.0.rc4 1.0.rc4.x