Anfälligkeitssuche        Suche in 187964 CVE Beschreibungen
und 85075 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800030
Kategorie:Privilege escalation
Titel:Dovecot ACL Plugin Security Bypass Vulnerabilities
Zusammenfassung:This host has Dovecot ACL Plugin installed and is prone to; multiple security bypass vulnerabilities.
Beschreibung:Summary:
This host has Dovecot ACL Plugin installed and is prone to
multiple security bypass vulnerabilities.

Vulnerability Insight:
The flaws are due to:

- the ACL plugin interprets negative access rights as positive access rights,
potentially giving an unprivileged user access to restricted resources.

- an error in the ACL plugin when imposing mailbox creation restrictions to
to create parent/child/child mailboxes.

Vulnerability Impact:
Successful attack could allow malicious people to bypass certain
security restrictions or manipulate certain data.

Affected Software/OS:
Dovecot versions prior to 1.1.4.

Solution:
Upgrade to Dovecot version 1.1.4 or later.

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:N

Querverweis: BugTraq ID: 31587
Common Vulnerability Exposure (CVE) ID: CVE-2008-4577
http://www.securityfocus.com/bid/31587
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00816.html
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00844.html
http://security.gentoo.org/glsa/glsa-200812-16.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:232
http://www.dovecot.org/list/dovecot-news/2008-October/000085.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376
http://www.redhat.com/support/errata/RHSA-2009-0205.html
http://secunia.com/advisories/32164
http://secunia.com/advisories/32471
http://secunia.com/advisories/33149
http://secunia.com/advisories/33624
http://secunia.com/advisories/36904
SuSE Security Announcement: SUSE-SR:2009:004 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
http://www.ubuntu.com/usn/USN-838-1
http://www.vupen.com/english/advisories/2008/2745
Common Vulnerability Exposure (CVE) ID: CVE-2008-4578
Bugtraq: 20081119 Re: [ MDVSA-2008:232 ] dovecot (Google Search)
http://www.securityfocus.com/archive/1/498498/100/0/threaded
XForce ISS Database: dovecot-acl-mailbox-security-bypass(45669)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45669
CopyrightCopyright (C) 2008 Greenbone Networks GmbH

Dies ist nur einer von 85075 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2020 E-Soft Inc. Alle Rechte vorbehalten.