Descriptiondovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
NVD severitylow

dovecot (PTS)jessie1:2.2.13-12~deb8u4vulnerable
jessie (security)1:2.2.13-12~deb8u7vulnerable
stretch (security), stretch1:2.2.27-3+deb9u5vulnerable
buster, buster (security)1:
bullseye, sid1:

by default this file doesnt containt sensitive information and administrator
changing this should ensure on its own that the mode is secure

