Bug 467437 (CVE-2008-4578)
| Summary: | CVE-2008-4578 dovecot: bypass of the 'k' right in the ACL plugin | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED WONTFIX | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | bressers, dan, mhlavink |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4578 | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2008-10-24 18:49:00 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Tomas Hoger
2008-10-17 14:16:13 UTC
This issue does not affect Dovecot version as shipped with Red Hat Enterprise Linux 4, as it does not include ACL plugin at all. This issue affects Dovecot version as shipped in Red Hat Enterprise Linux 5. However, this does not affect mailbox format used by default -- mbox -- as with this format, it's not possible to create child mailboxes (http://wiki.dovecot.org/MailboxFormat/mbox). However, this affects other non-default mailbox formats, such as Maildir. This is a low impact issue, as it only allows (in certain configurations) IMAP users to create child mailboxes where they should not be allowed to so. Original report of this problem on the Dovecot mailinglist: http://dovecot.org/list/dovecot/2008-September/033450.html The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 5. |