>> Dovecot ACL Plugin Rights Handling Security Bypass Vulnerabilities
Title : Dovecot ACL Plugin Rights Handling Security Bypass Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2745 CVE ID : CVE-2008-4577 - CVE-2008-4578 CWE ID : CWE-264
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-07
Technical Description
Multiple vulnerabilities have been identified in Dovecot, which could be exploited by malicious users to bypass security restrictions. These issues are caused by errors in the ACL plugin that does not properly handle defined rights, which could be exploited by malicious users to bypass intended restrictions and e.g. create parent/child/child mailboxes.