From owner-freebsd-ports-bugs@FreeBSD.ORG Wed Nov 19 22:00:12 2008 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3F1D61065672; Wed, 19 Nov 2008 22:00:12 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 197E08FC13; Wed, 19 Nov 2008 22:00:12 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.3/8.14.3) with ESMTP id mAJM0B1f007470; Wed, 19 Nov 2008 22:00:11 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.3/8.14.3/Submit) id mAJM0Bks007442; Wed, 19 Nov 2008 22:00:11 GMT (envelope-from gnats) Resent-Date: Wed, 19 Nov 2008 22:00:11 GMT Resent-Message-Id: <200811192200.mAJM0Bks007442@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@freebsd.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Cc: freebsd-security@freebsd.org, yds@CoolRat.org, delphij@freebsd.org Resent-Reply-To: FreeBSD-gnats-submit@freebsd.org, Eygene Ryabinkin Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id C31BD106564A for ; Wed, 19 Nov 2008 22:00:01 +0000 (UTC) (envelope-from rea-fbsd@codelabs.ru) Received: from 0.mx.codelabs.ru (0.mx.codelabs.ru [144.206.177.45]) by mx1.freebsd.org (Postfix) with ESMTP id 62D4B8FC13 for ; Wed, 19 Nov 2008 22:00:01 +0000 (UTC) (envelope-from rea-fbsd@codelabs.ru) Received: from phoenix.codelabs.ru (ppp85-141-163-250.pppoe.mtu-net.ru [85.141.163.250]) by 0.mx.codelabs.ru with esmtps (TLSv1:CAMELLIA256-SHA:256) id 1L2v5c-0009nP-8N for FreeBSD-gnats-submit@freebsd.org; Thu, 20 Nov 2008 01:00:00 +0300 Message-Id: <20081119215959.9FC17F181F@phoenix.codelabs.ru> Date: Thu, 20 Nov 2008 00:59:59 +0300 (MSK) From: Eygene Ryabinkin To: FreeBSD-gnats-submit@freebsd.org X-Send-Pr-Version: 3.113 X-GNATS-Notify: freebsd-security@freebsd.org, yds@CoolRat.org, delphij@freebsd.org Cc: Subject: ports/129000: [vuxml] mail/dovecot: document CVE-2008-4577 and CVE-2008-4578 X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Eygene Ryabinkin List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Nov 2008 22:00:12 -0000 >Number: 129000 >Category: ports >Synopsis: [vuxml] mail/dovecot: document CVE-2008-4577 and CVE-2008-4578 >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Wed Nov 19 22:00:10 UTC 2008 >Closed-Date: >Last-Modified: >Originator: Eygene Ryabinkin >Release: FreeBSD 7.1-PRERELEASE i386 >Organization: Code Labs >Environment: System: FreeBSD 7.1-PRERELEASE i386 >Description: There were two vulnerabilities in the ACL handling for Dovecot prior to the 1.1.4 [1]: ----- - ACL plugin fixes: Negative rights were actually treated as positive rights. 'k' right didn't prevent creating parent/child/child mailbox. ACL groups weren't working. ----- [1] http://www.dovecot.org/list/dovecot-news/2008-October/000085.html >How-To-Repeat: http://www.dovecot.org/list/dovecot-news/2008-October/000085.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4577 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4578 >Fix: The following VuXML entry should be evaluated and added: --- vuln.xml begins here --- dovecot -- two ACL bypassing vulnerabilities dovecot 1.1.6

Dovecot 1.1.4 release announcement says:

ACL plugin fixes: Negative rights were actually treated as positive rights. 'k' right didn't prevent creating parent/child/child mailbox. ACL groups weren't working.

CVE-2008-4577 http://www.dovecot.org/list/dovecot-news/2008-October/000085.html 2008-10-05
--- vuln.xml ends here --- I am putting '< 1.1.6' because FreeBSD ports version line was the following: ... -> 1.1.3 -> 1.1.6. >Release-Note: >Audit-Trail: >Unformatted: