Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 240409 (CVE-2008-4577)

Summary: net-mail/dovecot < 1.1.4 acl_plugin privilege escalation (CVE-2008-4577,CVE-2008-4578)
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: net-mail+disabled, wschlich
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://secunia.com/advisories/32164/
Whiteboard: B3? [glsa]
Package list:
Runtime testing required: ---

Description Robert Buchholz (RETIRED) gentoo-dev 2008-10-07 18:06:58 UTC
Secunia wrote:
Two security issues have been reported in Dovecot, which can be
exploited by malicious users to bypass certain security
restrictions.

1) The problem is that the ACL plugin interprets negative access
rights as positive access rights, potentially giving an unprivileged
user access to restricted resources.

2) An error in the ACL plugin when imposing mailbox creation
restrictions can be exploited to create "parent/child/child"
mailboxes.

The security issues are reported in versions prior to 1.1.4.

SOLUTION:
Update to version 1.1.4.

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
http://www.dovecot.org/list/dovecot-news/2008-October/000085.html
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-10-07 18:09:09 UTC
rating B3 since I would think only few people use this, and worst case should be data loss.
Comment 2 Wolfram Schlich (RETIRED) gentoo-dev 2008-10-08 08:15:33 UTC
1.1.4 is in the tree since 2008-10-06.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-10-08 08:47:28 UTC
Arches, please test and mark stable:
=net-mail/dovecot-1.1.4-r1
Target keywords : "alpha amd64 ppc sparc x86"
Comment 4 Markus Meier gentoo-dev 2008-10-08 19:15:31 UTC
amd64/x86 stable
Comment 5 Tobias Scherbaum (RETIRED) gentoo-dev 2008-10-11 17:49:41 UTC
ppc stable
Comment 6 Friedrich Oslage (RETIRED) gentoo-dev 2008-10-12 13:51:31 UTC
sparc stable
Comment 7 Raúl Porcel (RETIRED) gentoo-dev 2008-10-12 18:10:27 UTC
alpha stable
Comment 8 Robert Buchholz (RETIRED) gentoo-dev 2008-11-09 13:06:37 UTC
yes with 244962
Comment 9 Tobias Heinlein (RETIRED) gentoo-dev 2008-11-30 18:39:18 UTC
YES too, request already in the pool.
Comment 10 Tobias Heinlein (RETIRED) gentoo-dev 2008-12-15 13:53:56 UTC
GLSA 200812-16, thanks everyone, sorry about the delay.