CVE-2008-1199: Medium severity dovecot vulnerability
Dovecot before 1.0.11, when configured to use mailextragroups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1199?
CVE-2008-1199 is considered a moderate severity vulnerability due to its potential to expose sensitive mail files.
How do I fix CVE-2008-1199?
To fix CVE-2008-1199, upgrade Dovecot to version 1.0.11 or later where the vulnerability has been addressed.
What impact does CVE-2008-1199 have on users?
CVE-2008-1199 may allow local users to read or modify mail files of other users due to improper symlink handling.
Which versions of Dovecot are affected by CVE-2008-1199?
CVE-2008-1199 affects Dovecot versions prior to 1.0.11, including various beta and release candidates.
Is CVE-2008-1199 a local or remote vulnerability?
CVE-2008-1199 is a local vulnerability that requires local access to exploit.