Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2008-1199

Published: 6 March 2008

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

Priority

Medium

Status

Package Release Status
dovecot
Launchpad, Ubuntu, Debian
dapper
Released (1.0.beta3-3ubuntu5.6)
edgy
Released (1.0.rc2-1ubuntu2.3)
feisty
Released (1.0.rc17-1ubuntu2.3)
gutsy
Released (1:1.0.5-1ubuntu2.2)
upstream
Released (1.0.11)