Oval Definition:oval:org.mitre.oval:tst:36019
Comment:dovecot is earlier than 0:1.0.7-2.el5
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14550
Object:oval:org.mitre.oval:obj:3572
State:oval:org.mitre.oval:ste:10407
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:10458
V
Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
2013-04-29
oval:org.mitre.oval:def:10739
V
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
2013-04-29
oval:org.mitre.oval:def:10995
V
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
2013-04-29
oval:org.mitre.oval:def:11558
V
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
2013-04-29
BACK