Oval Definition:oval:org.mitre.oval:tst:38149
Comment:dovecot is earlier than 0:1.0.7-7.el5
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14550
Object:oval:org.mitre.oval:obj:3572
State:oval:org.mitre.oval:ste:11139
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:10376
V
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
2013-04-29
oval:org.mitre.oval:def:10776
V
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
2013-04-29
BACK