Novell Home

CVE-2008-4577

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

CVE-2008-4577 at MITRE

Details

The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
Novell Bugzilla entry: 435978

SUSE Security Advisories:

Product(s) Fixed package version(s) References
openSUSE 10.3
  • dovecot >= 1.0.5-6.4
  • dovecot-devel >= 1.0.5-6.4
ZYPP Patch Nr: 5986
SAT Patch Nr: 504
openSUSE 11.0
  • dovecot-debuginfo >= 1.0.13-24.2
  • dovecot-debugsource >= 1.0.13-24.2
ZYPP Patch Nr: 5986
SAT Patch Nr: 504
openSUSE 11.0
  • dovecot >= 1.0.13-24.2
  • dovecot-devel >= 1.0.13-24.2
ZYPP Patch Nr: 5986
SAT Patch Nr: 504

Novell® Making IT Work As One

© 2009 Novell, Inc. All Rights Reserved.