CVE-2008-4870 (dovecot) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-4870 (dovecot)


Heap
04-11-08, 02:44
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.

More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4870)