Bug 467437 (CVE-2008-4578) - CVE-2008-4578 dovecot: bypass of the 'k' right in the ACL plugin
Summary: CVE-2008-4578 dovecot: bypass of the 'k' right in the ACL plugin
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2008-4578
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-10-17 14:16 UTC by Tomas Hoger
Modified: 2021-11-12 19:53 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-10-24 18:49:00 UTC
Embargoed:


Attachments (Terms of Use)

Description Tomas Hoger 2008-10-17 14:16:13 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4578 to the following vulnerability:

The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass
intended access restrictions by using the "k" right to create
unauthorized "parent/child/child" mailboxes.

Upstream patch:
http://hg.dovecot.org/dovecot-1.1/rev/d2657188377b

References:
http://www.dovecot.org/list/dovecot-news/2008-October/000085.html
http://bugs.gentoo.org/show_bug.cgi?id=240409
http://www.securityfocus.com/bid/31587
http://www.frsirt.com/english/advisories/2008/2745
http://secunia.com/advisories/32164

Comment 2 Tomas Hoger 2008-10-21 12:55:43 UTC
This issue does not affect Dovecot version as shipped with Red Hat Enterprise
Linux 4, as it does not include ACL plugin at all.

This issue affects Dovecot version as shipped in Red Hat Enterprise Linux 5.  However, this does not affect mailbox format used by default -- mbox -- as with this format, it's not possible to create child mailboxes (http://wiki.dovecot.org/MailboxFormat/mbox).  However, this affects other non-default mailbox formats, such as Maildir.

This is a low impact issue, as it only allows (in certain configurations) IMAP users to create child mailboxes where they should not be allowed to so.

Comment 3 Tomas Hoger 2008-10-21 12:57:06 UTC
Original report of this problem on the Dovecot mailinglist:

http://dovecot.org/list/dovecot/2008-September/033450.html

Comment 4 Josh Bressers 2008-10-24 18:49:00 UTC
The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 5.


Note You need to log in before you can comment on or make changes to this bug.