Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-03-06 13:44
Updated : 2018-10-11 13:30
NVD link : CVE-2008-1199
Mitre link : CVE-2008-1199
JSON object : View
Products Affected
dovecot
- dovecot