Novell Home

CVE-2008-4577

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-4577 at MITRE

Description

The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.

NVD CVSS v2 Base Score: 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N)

Novell/SUSE information

Novell Bugzilla entry: 435978

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • dovecot >= 1.0.5-6.4
  • dovecot-devel >= 1.0.5-6.4

© 2012 Novell