CVE-2009-3897

NameCVE-2009-3897
DescriptionDovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs557601

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dovecot (PTS)bookworm, bookworm (security)1:2.3.19.1+dfsg1-2.1+deb12u6fixed
trixie (security), trixie1:2.4.1+dfsg1-6+deb13u6fixed
forky1:2.4.4+dfsg1-2fixed
sid1:2.4.5+dfsg1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dovecotsourceetch(not affected)
dovecotsourcelenny(not affected)
dovecotsource(unstable)1:1.2.8-1medium557601

Notes

[lenny] - dovecot <not-affected> (Only affects 1.2.x)
[etch] - dovecot <not-affected> (Only affects 1.2.x)

Search for package or bug name: Reporting problems