PT-2008-6048 · Dovecot+2 · Dovecot+2
Published
2008-10-31
·
Updated
2022-02-03
·
CVE-2008-4870
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
dovecot version 1.0.7
Description
The issue allows local users to obtain the
ssl key password parameter value due to world-readable permissions for dovecot.conf.Recommendations
For dovecot version 1.0.7, consider changing the permissions of dovecot.conf to restrict access and prevent unauthorized users from reading the configuration file, specifically to protect the
ssl key password parameter.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Red Hat
Dovecot