CVE-2008-1199
Summary
| CVE | CVE-2008-1199 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-03-06 21:44:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack. |
Risk And Classification
Primary CVSS: v2.0 4.4 from [email protected]
AV:L/AC:M/Au:N/C:P/I:P/A:P
Problem Types: CWE-16 | CWE-59 | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dovecot | Dovecot | 0.99.13 | All | All | All |
| Application | Dovecot | Dovecot | 0.99.14 | All | All | All |
| Application | Dovecot | Dovecot | 1.0 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.10 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.2 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.3 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.4 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.5 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.6 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.7 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.8 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.9 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta2 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta3 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta7 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta8 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc1 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc10 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc11 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc12 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc13 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc14 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc15 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc2 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc3 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc4 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc5 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc6 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc7 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc8 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc9 | All | All | All |
| Application | Dovecot | Dovecot | 1.0_rc29 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fedora update for dovecot - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Dovecot: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| USN-593-1: Dovecot vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| Gentoo update for dovecot - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat update for dovecot - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Ubuntu update for dovecot - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| [Dovecot-news] v1.0.11 released | af854a3a-2127-422b-91ae-364da2661108 | www.dovecot.org | Patch |
| Debian -- Security Information -- DSA-1516-1 dovecot | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [SECURITY] Fedora 8 Update: dovecot-1.0.13-6.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [SECURITY] Fedora 7 Update: dovecot-1.0.13-18.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian update for dovecot - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Dovecot 'mail_extra_groups' Insecure Settings Local Unauthorized Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2008:020 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SUSE update for dovecot and graphicsmagic - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-05-21 | Joshua Bressers | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2008-1199 This issue does not affect the default configuration of Dovecot as shipped in Red Hat Enterprise Linux. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw. An update to Red Hat Enterprise Linux 5 was released to correct this issue: https://rhn.redhat.com/errata/RHSA-2008-0297.html |
There are currently no legacy QID mappings associated with this CVE.