CVE-2008-4578

The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
dovecotdovecot
𝑥
≤ 1.1.3
dovecotdovecot
0.99.13
dovecotdovecot
0.99.14
dovecotdovecot
1.0
dovecotdovecot
1.0.2
dovecotdovecot
1.0.3
dovecotdovecot
1.0.4
dovecotdovecot
1.0.5
dovecotdovecot
1.0.6
dovecotdovecot
1.0.7
dovecotdovecot
1.0.8
dovecotdovecot
1.0.9
dovecotdovecot
1.0.10
dovecotdovecot
1.0.12
dovecotdovecot
1.0.beta1:beta1
dovecotdovecot
1.0.beta2:beta2
dovecotdovecot
1.0.beta3:beta3
dovecotdovecot
1.0.beta4:beta4
dovecotdovecot
1.0.beta5:beta5
dovecotdovecot
1.0.beta6:beta6
dovecotdovecot
1.0.beta7:beta7
dovecotdovecot
1.0.beta8:beta8
dovecotdovecot
1.0.beta9:beta9
dovecotdovecot
1.0.rc1:rc1
dovecotdovecot
1.0.rc2:rc2
dovecotdovecot
1.0.rc3:rc3
dovecotdovecot
1.0.rc4:rc4
dovecotdovecot
1.0.rc5:rc5
dovecotdovecot
1.0.rc6:rc6
dovecotdovecot
1.0.rc7:rc7
dovecotdovecot
1.0.rc8:rc8
dovecotdovecot
1.0.rc9:rc9
dovecotdovecot
1.0.rc10:rc10
dovecotdovecot
1.0.rc11:rc11
dovecotdovecot
1.0.rc12:rc12
dovecotdovecot
1.0.rc13:rc13
dovecotdovecot
1.0.rc14:rc14
dovecotdovecot
1.0.rc15:rc15
dovecotdovecot
1.0.rc16:rc16
dovecotdovecot
1.0.rc17:rc17
dovecotdovecot
1.0.rc18:rc18
dovecotdovecot
1.0.rc19:rc19
dovecotdovecot
1.0.rc20:rc20
dovecotdovecot
1.0.rc21:rc21
dovecotdovecot
1.0.rc22:rc22
dovecotdovecot
1.0.rc23:rc23
dovecotdovecot
1.0.rc24:rc24
dovecotdovecot
1.0.rc25:rc25
dovecotdovecot
1.0.rc26:rc26
dovecotdovecot
1.0.rc27:rc27
dovecotdovecot
1.0.rc28:rc28
dovecotdovecot
1.0_rc29:_rc29
dovecotdovecot
1.1
dovecotdovecot
1.1:rc2
dovecotdovecot
1.1.0
dovecotdovecot
1.1.1
dovecotdovecot
1.1.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dovecot
bullseye
1:2.3.13+dfsg1-2+deb11u1
fixed
etch
no-dsa
lenny
no-dsa
bullseye (security)
1:2.3.13+dfsg1-2+deb11u2
fixed
bookworm
1:2.3.19.1+dfsg1-2.1+deb12u1
fixed
bookworm (security)
1:2.3.19.1+dfsg1-2.1+deb12u1
fixed
sid
1:2.3.21.1+dfsg1-1
fixed
trixie
1:2.3.21.1+dfsg1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dovecot
intrepid
not-affected
hardy
ignored
gutsy
ignored
dapper
not-affected
Common Weakness Enumeration