[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 16 Sep 2010 20:34:41 +0300
From: Henri Salo <henri@...v.fi>
To: "oss-security" <oss-security@...ts.openwall.com>
Subject: CVE-identifier request for Dovecot ACL security bug
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Can I get CVE-identifier for this issue?
"This release fixes a bug in ACL plugin, which could be considered a
security bug: If Maildir is used with default settings (INBOX is same
as Maildir root dir) and user set some ACLs to INBOX, those ACLs were
copied to all newly created mailboxes. This should have been done only
for "default ACLs", but with Maildir the INBOX directory is the same as
the default ACL directory, so this mixup happened. This bug exists only
in v1.2.x releases."
URL to announcement:
http://www.dovecot.org/list/dovecot-news/2010-July/000163.html
Please note that this is different issue than: CVE-2010-0745
Best regards,
Henri Salo
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkySVTEACgkQXf6hBi6kbk9r9wCgs6z72LRTcywrsWIPtRiAR/R0
fxcAoLQuYxA3NDFPsUiUhe7uTBm6c5xI
=nWSw
-----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ