Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.801055
Categoría:Privilege escalation
Título:Dovecot 'base_dir' Insecure Permissions Security Bypass Vulnerability
Resumen:Dovecot is prone to a security bypass vulnerability.
Descripción:Summary:
Dovecot is prone to a security bypass vulnerability.

Vulnerability Insight:
This flaw is due to insecure permissions (0777) being set on the 'base_dir'
directory and its parents, which could allow malicious users to replace auth
sockets and log in as other users.

Vulnerability Impact:
Successful attack could allow malicious people to log in as another user,
which may aid in further attacks.

Affected Software/OS:
Dovecot versions 1.2 before 1.2.8.

Solution:
Apply the patch or upgrade to Dovecot version 1.2.8.

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-3897
37084
http://www.securityfocus.com/bid/37084
37443
http://secunia.com/advisories/37443
60316
http://www.osvdb.org/60316
ADV-2009-3306
http://www.vupen.com/english/advisories/2009/3306
MDVSA-2009:306
http://www.mandriva.com/security/advisories?name=MDVSA-2009:306
SUSE-SR:2010:001
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html
[dovecot-news] 20091120 v1.2.8 released
http://www.dovecot.org/list/dovecot-news/2009-November/000143.html
[oss-security] 20091120 CVE request: v1.2.8 released to fix the 0777 base_dir creation issue
http://marc.info/?l=oss-security&m=125871729029145&w=2
[oss-security] 20091121 CVE Request - Dovecot - 1.2.8
http://marc.info/?l=oss-security&m=125881481222441&w=2
[oss-security] 20091123 Re: CVE Request - Dovecot - 1.2.8
http://marc.info/?l=oss-security&m=125900271508796&w=2
[oss-security] 20091123 Re: CVE request: v1.2.8 released to fix the 0777 base_dir creation issue
http://marc.info/?l=oss-security&m=125900267208712&w=2
dovecot-basedir-privilege-escalation(54363)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54363
CopyrightCopyright (C) 2009 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.