CVE DATABASE / CVE-2008-4577
CVE-2008-4577
CVSS 7.5 · HIGH
Summary
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
CVSS 3.1 breakdown
| Base score | 7.5 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity | NONE |
| Availability | NONE |
Weakness type (CWE)
Affected products
Dovecot dovecotFedoraproject fedoraOpensuse opensuseCanonical ubuntu linux
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://bugs.gentoo.org/show_bug.cgi?id=240409
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
- http://secunia.com/advisories/32164
- http://secunia.com/advisories/32471
- http://secunia.com/advisories/33149
- http://secunia.com/advisories/33624
- http://secunia.com/advisories/36904
- http://security.gentoo.org/glsa/glsa-200812-16.xml
- http://www.dovecot.org/list/dovecot-news/2008-October/000085.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:232
- http://www.redhat.com/support/errata/RHSA-2009-0205.html
- http://www.securityfocus.com/bid/31587
- http://www.ubuntu.com/usn/USN-838-1
- http://www.vupen.com/english/advisories/2008/2745
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10376
Data: NIST NVD. NVD last modified 2026-04-23. Always verify against the vendor advisory before acting.