CVE-2008-1199

Publication date 6 March 2008

Last updated 24 July 2024


Ubuntu priority

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

Status

Package Ubuntu Release Status
dovecot 7.10 gutsy
Fixed 1:1.0.5-1ubuntu2.2
7.04 feisty
Fixed 1.0.rc17-1ubuntu2.3
6.10 edgy
Fixed 1.0.rc2-1ubuntu2.3
6.06 LTS dapper
Fixed 1.0.beta3-3ubuntu5.6

References

Related Ubuntu Security Notices (USN)

    • USN-593-1
    • Dovecot vulnerabilities
    • 26 March 2008

Other references