Description of problem: A new version of dovecot was issued, The announcement (see URL) reads: - ACL plugin: If user was given i (insert) right for a mailbox, but not all s/t/w (seen, deleted, other flags) rights, COPY and APPEND commands weren't supposed to allow saving those flags. This is technically a security fix, but it's unlikely this caused problems for anyone. Version-Release number of selected component (if applicable): Affects: FC7 Affects: FC6 Affects: RHEL5 Doesn't Affect: RHEL4 (no ACL plugin) Doesn't Affect: RHEL3 (dovecot not shipped) Doesn't Affect: RHEL2.1 (dovecot not shipped)
Upstream fixed in 1.0.3: http://www.dovecot.org/list/dovecot-news/2007-August/000048.html All current Fedora versions ship fixed upstream version. Red Hat Enterprise Linux 5 fixed via: http://rhn.redhat.com/errata/RHSA-2008-0297.html
Reporter changed to security-response-team by request of Jay Turner.