2.1 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
0.0004 Low
EPSS
Percentile
5.1%
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | dovecot | <= 1:2.3.19.1+dfsg1-2.1 | dovecot_1:2.3.19.1+dfsg1-2.1_all.deb |
Debian | 11 | all | dovecot | <= 1:2.3.13+dfsg1-2+deb11u1 | dovecot_1:2.3.13+dfsg1-2+deb11u1_all.deb |
Debian | 999 | all | dovecot | <= 1:2.3.21+dfsg1-3 | dovecot_1:2.3.21+dfsg1-3_all.deb |
Debian | 13 | all | dovecot | <= 1:2.3.21+dfsg1-3 | dovecot_1:2.3.21+dfsg1-3_all.deb |