CVE-2009-3897
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir…
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- dovecot/dovecot
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.htmlMailing List
- http://marc.info/?l=oss-security&m=125871729029145&w=2Mailing List, Patch
- http://marc.info/?l=oss-security&m=125881481222441&w=2Mailing List
- http://marc.info/?l=oss-security&m=125900267208712&w=2Mailing List, Patch
- http://marc.info/?l=oss-security&m=125900271508796&w=2Mailing List
- http://secunia.com/advisories/37443Broken Link, Vendor Advisory
- http://www.dovecot.org/list/dovecot-news/2009-November/000143.htmlMailing List, Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:306Not Applicable
- http://www.osvdb.org/60316Broken Link
- http://www.securityfocus.com/bid/37084Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/3306Patch, Permissions Required, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54363Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.htmlMailing List
- http://marc.info/?l=oss-security&m=125871729029145&w=2Mailing List, Patch
- http://marc.info/?l=oss-security&m=125881481222441&w=2Mailing List
- http://marc.info/?l=oss-security&m=125900267208712&w=2Mailing List, Patch
- http://marc.info/?l=oss-security&m=125900271508796&w=2Mailing List
- http://secunia.com/advisories/37443Broken Link, Vendor Advisory
- http://www.dovecot.org/list/dovecot-news/2009-November/000143.htmlMailing List, Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:306Not Applicable
- http://www.osvdb.org/60316Broken Link
- http://www.securityfocus.com/bid/37084Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/3306Patch, Permissions Required, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54363Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.