Secunia wrote: Two security issues have been reported in Dovecot, which can be exploited by malicious users to bypass certain security restrictions. 1) The problem is that the ACL plugin interprets negative access rights as positive access rights, potentially giving an unprivileged user access to restricted resources. 2) An error in the ACL plugin when imposing mailbox creation restrictions can be exploited to create "parent/child/child" mailboxes. The security issues are reported in versions prior to 1.1.4. SOLUTION: Update to version 1.1.4. PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://www.dovecot.org/list/dovecot-news/2008-October/000085.html
rating B3 since I would think only few people use this, and worst case should be data loss.
1.1.4 is in the tree since 2008-10-06.
Arches, please test and mark stable: =net-mail/dovecot-1.1.4-r1 Target keywords : "alpha amd64 ppc sparc x86"
amd64/x86 stable
ppc stable
sparc stable
alpha stable
yes with 244962
YES too, request already in the pool.
GLSA 200812-16, thanks everyone, sorry about the delay.