CVE-2008-3579: High severity linux kernel vulnerability
Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the entire @Mail directory tree. NOTE: this can be leveraged for remote exploitation of CVE-2008-3395. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3579?
CVE-2008-3579 is considered a high severity vulnerability due to its potential for remote exploitation and information disclosure.
How do I fix CVE-2008-3579?
To fix CVE-2008-3579, ensure that administrative authentication is required for the build-plesk-upgrade.php file and update to a patched version of Calacode Atmail.
Who is affected by CVE-2008-3579?
CVE-2008-3579 affects users of Calacode Atmail version 5.41 running on Linux.
What type of attack can be executed with CVE-2008-3579?
CVE-2008-3579 allows remote attackers to create and download backup archives containing sensitive information from the @Mail directory.
Is CVE-2008-3579 related to any specific software?
Yes, CVE-2008-3579 specifically targets the Calacode Atmail Webmail System version 5.41.