Vulnerability Name: | CVE-2008-5301 (CCN-46672) |
Assigned: | 2008-11-17 |
Published: | 2008-11-17 |
Updated: | 2017-08-08 |
Summary: | Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-22
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2008-5301
Source: CCN Type: Dovecot-news Mailing List, Mon Nov 17 21:45:33 EET 2008 ManageSieve SECURITY hole: virtual users can edit scripts of other virtual users (all versions)
Source: CCN Type: SA32768 Dovecot ManageSieve Directory Traversal Security Issue
Source: SECUNIA Type: Vendor Advisory 32768
Source: SECUNIA Type: UNKNOWN 36904
Source: CCN Type: Dovecot Download Web site Download
Source: MLIST Type: Patch [Dovecot] 20081117 ManageSieve SECURITY hole: virtual users can edit scripts of other virtual users (all versions)
Source: CCN Type: OSVDB ID: 49918 Dovecot ManageSieve Script Name Handling Traversal Arbitrary File Manipulation
Source: BID Type: UNKNOWN 32582
Source: CCN Type: BID-32582 Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
Source: CCN Type: USN-838-1 Dovecot vulnerabilities
Source: UBUNTU Type: UNKNOWN USN-838-1
Source: VUPEN Type: UNKNOWN ADV-2008-3190
Source: XF Type: UNKNOWN managesieve-sieve-directory-traversal(46672)
Source: XF Type: UNKNOWN managesieve-sieve-directory-traversal(46672)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:dovecot:dovecot:0.99.13:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:0.99.14:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.2:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.3:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.4:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.5:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.6:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.7:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.8:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.9:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.10:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.12:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1:rc2:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.0:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.1:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.2:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.3:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.4:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.5:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:dovecot:dovecot:1.0.12:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.0.10:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.4:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.3:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.2:*:*:*:*:*:*:*OR cpe:/a:dovecot:dovecot:1.1.1:*:*:*:*:*:*:*AND cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |