Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Lightbulb Dovecot v1.2 security alert


  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    598

    Default

    Can anyone confirm or gainsay if this affects the dovecot version 1.1.19 that cpanel uses?

    And if so when will a fix be available?

    I ran upcp just now and still have version 1.1.19

    TIA

  3. #3
    cPanel Quality Assurance Analyst cPanelDon's Avatar
    Join Date
    Nov 2008
    Location
    Houston, Texas, U.S.A.
    Posts
    2,554
    cPanel/Enkompass Access Level

    DataCenter Provider

    Lightbulb

    According to both the vendor and the third-party "secunia" link the issue only affects Dovecot releases in the version 1.2 series that were released prior to version 1.2.8; this does not affect the Dovecot version 1.1 series used by cPanel.

    Reference: [Dovecot-news] v1.2.8 released
    This is mainly to fix the 0777 base_dir creation issue, which could be considered a security hole, exploitable by local users. An attacker could for example replace Dovecot's auth socket and log in as other users. Gaining root privileges isn't possible though.

    This affects only v1.2 users, v1.1 and older versions were creating the directory with 0755 permission.

Similar Threads & Tags
Similar threads

  1. Security Alert!
    By sexy_guy in forum cPanel and WHM Discussions
    Replies: 64
    Last Post: 05-26-2006, 05:28 AM
  2. Security Alert
    By devellion in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 04-04-2006, 04:26 AM
  3. Security Alert
    By engrkhalid in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-24-2004, 02:36 AM
  4. Should I be Security Alert?
    By Doctor in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 12-11-2003, 04:56 AM
  5. security alert in log
    By shann in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-20-2003, 03:40 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube