Date: Mon, 23 Nov 2009 13:58:11 -0500 (EST) From: Josh Bressers <bressers@...hat.com> To: oss-security@...ts.openwall.com Cc: "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: CVE Request - Dovecot - 1.2.8 This is CVE-2009-3897 (as noted in a previous mail), this is the second request for this flaw. Thanks. -- JB ----- "Jan Lieskovsky" <jlieskov@...hat.com> wrote: > Hi Josh, Steve, vendors, > > Dovecot upstream has released latest 1.2.8 version, fixing > one security issue. Quoting from news: > > This is mainly to fix the 0777 base_dir creation issue, which could > be > considered a security hole, exploitable by local users. An attacker > could for example replace Dovecot's auth socket and log in as other > users. Gaining root privileges isn't possible though. > > This affects only v1.2 users, v1.1 and older versions were creating > the > directory with 0755 permission. > > References: > ----------- > http://www.dovecot.org/list/dovecot-news/2009-November/000143.html > http://www.dovecot.org/index.html > > Could you allocate a CVE id? (in case there isn't one already). > > Thanks && Regards, Jan. > -- > Jan iankko Lieskovsky / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.