Two security issues have been reported in Dovecot, which can be
exploited by malicious users to bypass certain security
1) The problem is that the ACL plugin interprets negative access
rights as positive access rights, potentially giving an unprivileged
user access to restricted resources.
2) An error in the ACL plugin when imposing mailbox creation
restrictions can be exploited to create "parent/child/child"
The security issues are reported in versions prior to 1.1.4.
Update to version 1.1.4.
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
rating B3 since I would think only few people use this, and worst case should be data loss.
1.1.4 is in the tree since 2008-10-06.
Arches, please test and mark stable:
Target keywords : "alpha amd64 ppc sparc x86"
yes with 244962
YES too, request already in the pool.
GLSA 200812-16, thanks everyone, sorry about the delay.