Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.vupen.com/english/advisories/2008/3190
http://secunia.com/Advisories/32768/
http://dovecot.org/list/dovecot/2008-November/035259.html http://www.vuxml.org/freebsd/3efc106e-c451-11dd-a721-0030843d3802.html
Insight
The following package is affected: dovecot-managesieve
CVE-2008-5301
Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a '..' (dot dot) in a script name.
Severity
Classification
-
CVE CVE-2008-5301 -
CVSS Base Score: 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:N
Related Vulnerabilities