CVE-2008-4578
Summary
| CVE | CVE-2008-4578 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-15 20:08:02 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dovecot | Dovecot | 0.99.13 | All | All | All |
| Application | Dovecot | Dovecot | 0.99.14 | All | All | All |
| Application | Dovecot | Dovecot | 1.0 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.10 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.12 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.2 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.3 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.4 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.5 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.6 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.7 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.8 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.9 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta1 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta2 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta3 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta4 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta5 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta6 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta7 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta8 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.beta9 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc1 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc10 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc11 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc12 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc13 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc14 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc15 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc16 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc17 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc18 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc19 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc2 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc20 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc21 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc22 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc23 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc24 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc25 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc26 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc27 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc28 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc3 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc4 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc5 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc6 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc7 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc8 | All | All | All |
| Application | Dovecot | Dovecot | 1.0.rc9 | All | All | All |
| Application | Dovecot | Dovecot | 1.0_rc29 | All | All | All |
| Application | Dovecot | Dovecot | 1.1 | All | All | All |
| Application | Dovecot | Dovecot | 1.1 | rc2 | All | All |
| Application | Dovecot | Dovecot | 1.1.0 | All | All | All |
| Application | Dovecot | Dovecot | 1.1.1 | All | All | All |
| Application | Dovecot | Dovecot | 1.1.2 | All | All | All |
| Application | Dovecot | Dovecot | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Gentoo update for dovecot - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Dovecot ACL Plugin Multiple Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Dovecot ACL Plugin Security Bypass Security Issues - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Gentoo Bug 240409 - net-mail/dovecot < 1.1.4 acl_plugin privilege escalation (CVE-2008-4577,CVE-2008-4578) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| [Dovecot-news] v1.1.4 released | af854a3a-2127-422b-91ae-364da2661108 | www.dovecot.org | Patch |
| Support / Security / Advisories / / MDVSA-2008:232 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Dovecot: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-10-24 | Joshua Bressers | The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 5. |
There are currently no legacy QID mappings associated with this CVE.