Vulnerability Name: | CVE-2009-3897 (CCN-54363) | ||||||||
Assigned: | 2009-11-20 | ||||||||
Published: | 2009-11-20 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3897 Source: SUSE Type: UNKNOWN SUSE-SR:2010:001 Source: MLIST Type: Patch [oss-security] 20091120 CVE request: v1.2.8 released to fix the 0777 base_dir creation issue Source: MLIST Type: UNKNOWN [oss-security] 20091121 CVE Request - Dovecot - 1.2.8 Source: MLIST Type: Patch [oss-security] 20091123 Re: CVE request: v1.2.8 released to fix the 0777 base_dir creation issue Source: MLIST Type: UNKNOWN [oss-security] 20091123 Re: CVE Request - Dovecot - 1.2.8 Source: CCN Type: SA37443 Dovecot Insecure Directory Permissions Security Issue Source: SECUNIA Type: Vendor Advisory 37443 Source: CCN Type: Dovecot Download Web site Download Source: CCN Type: Dovecot-news v1.2.8 released Source: MLIST Type: Patch, Vendor Advisory [dovecot-news] 20091120 v1.2.8 released Source: MANDRIVA Type: UNKNOWN MDVSA-2009:306 Source: OSVDB Type: UNKNOWN 60316 Source: CCN Type: OSVDB ID: 60316 Dovecot base_dir Directory Permission Weakness Local Privilege Escalation Source: BID Type: Patch 37084 Source: CCN Type: BID-37084 Dovecot Insecure 'base_dir' Permissions Local Privilege Escalation Vulnerability Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-3306 Source: XF Type: UNKNOWN dovecot-basedir-privilege-escalation(54363) Source: XF Type: UNKNOWN dovecot-basedir-privilege-escalation(54363) Source: SUSE Type: SUSE-SR:2010:001 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |