Описание
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | |
devel | not-affected | 1:1.1.11-0ubuntu2 |
gutsy | ignored | end of life, was needed |
hardy | ignored | |
intrepid | ignored | end of life, was needed |
jaunty | not-affected | 1:1.1.11-0ubuntu2 |
karmic | not-affected | 1:1.1.11-0ubuntu2 |
lucid | not-affected | 1:1.1.11-0ubuntu2 |
upstream | released | 1.1.7 |
Показывать по
Ссылки на источники
EPSS
2.1 Low
CVSS2
Связанные уязвимости
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedor ...
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
ELSA-2009-0205: dovecot security and bug fix update (LOW)
EPSS
2.1 Low
CVSS2