Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-4870

Опубликовано: 01 нояб. 2008
Источник: debian
EPSS Низкий

Описание

dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dovecotunfixedpackage

Примечания

  • by default this file doesnt containt sensitive information and administrator

  • changing this should ensure on its own that the mode is secure

EPSS

Процентиль: 12%
0.0004
Низкий

Связанные уязвимости

redhat
больше 17 лет назад

dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.

nvd
больше 16 лет назад

dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.

github
около 3 лет назад

dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.

oracle-oval
больше 16 лет назад

ELSA-2009-0205: dovecot security and bug fix update (LOW)

EPSS

Процентиль: 12%
0.0004
Низкий