CVE-2008-4578

UnknownEPSS 1.68%

Last modified

CVE-2008-4578 is a vulnerability of currently unknown severity. The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.

Description

The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.

Metrics

EPSS Probability
1.68%

74.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DovecotDovecot<= 1.1.3
DovecotDovecot0.99.13
DovecotDovecot0.99.14
DovecotDovecot1.0
DovecotDovecot1.0.2
DovecotDovecot1.0.3
DovecotDovecot1.0.4
DovecotDovecot1.0.5
DovecotDovecot1.0.6
DovecotDovecot1.0.7
DovecotDovecot1.0.8
DovecotDovecot1.0.9
DovecotDovecot1.0.10
DovecotDovecot1.0.12
DovecotDovecot1.0.beta1
DovecotDovecot1.0.beta2
DovecotDovecot1.0.beta3
DovecotDovecot1.0.beta4
DovecotDovecot1.0.beta5
DovecotDovecot1.0.beta6
DovecotDovecot1.0.beta7
DovecotDovecot1.0.beta8
DovecotDovecot1.0.beta9
DovecotDovecot1.0.rc1
DovecotDovecot1.0.rc2
DovecotDovecot1.0.rc3
DovecotDovecot1.0.rc4
DovecotDovecot1.0.rc5
DovecotDovecot1.0.rc6
DovecotDovecot1.0.rc7
DovecotDovecot1.0.rc8
DovecotDovecot1.0.rc9
DovecotDovecot1.0.rc10
DovecotDovecot1.0.rc11
DovecotDovecot1.0.rc12
DovecotDovecot1.0.rc13
DovecotDovecot1.0.rc14
DovecotDovecot1.0.rc15
DovecotDovecot1.0.rc16
DovecotDovecot1.0.rc17
DovecotDovecot1.0.rc18
DovecotDovecot1.0.rc19
DovecotDovecot1.0.rc20
DovecotDovecot1.0.rc21
DovecotDovecot1.0.rc22
DovecotDovecot1.0.rc23
DovecotDovecot1.0.rc24
DovecotDovecot1.0.rc25
DovecotDovecot1.0.rc26
DovecotDovecot1.0.rc27

Showing 50 of 56 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-4578?
The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
How severe is CVE-2008-4578?
Severity scoring for CVE-2008-4578 is pending analysis. The EPSS model estimates a 1.68% probability of exploitation in the next 30 days.
How do I fix CVE-2008-4578?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-4578?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST