CVE-2008-4870: Low severity dovecot vulnerability
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the sslkeypassword parameter value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4870?
CVE-2008-4870 has been classified as a medium severity vulnerability due to its potential for local information disclosure.
How do I fix CVE-2008-4870?
To fix CVE-2008-4870, ensure that the permissions for dovecot.conf are restricted so that only authorized users can read the file.
Who is affected by CVE-2008-4870?
CVE-2008-4870 affects users running Dovecot version 1.0.7 on Red Hat Enterprise Linux 5 and possibly other systems.
What type of vulnerability is CVE-2008-4870?
CVE-2008-4870 is a local information disclosure vulnerability resulting from improper permissions on the Dovecot configuration file.
Can CVE-2008-4870 be exploited remotely?
No, CVE-2008-4870 requires local access to exploit the vulnerability, as it involves accessing a local configuration file.