Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Dovecot 'mail_extra_groups' 不安全设置本地授权访问漏洞
Vulnerability Description
Dovecot 1.0.11之前的版本存在不安全设置本地授权访问漏洞。当被设定成使用mail_extra_groups来允许Dovecot创建点锁定时,Dovecot 1.0.11之前的版本可能允许本地用户借助symlink攻击,读取其他用户的敏感的邮件文件,或者修改可群读的文件或目录。
CVSS Information
N/A
Vulnerability Type
N/A