yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2016-4983
Component Overview
Vulnerability Overview
Name
CVE-2016-4983
Source
NVD (
link
)
Debian (
link
)
Description
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
CWEs
CWE-732
Published Date
Nov 5, 2019
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://lists.opensuse.org/opensuse-updates/2016-11/msg00096.html
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1346055
Exploit
https://bugzilla.suse.com/show_bug.cgi?id=984639
Exploit
http://lists.opensuse.org/opensuse-updates/2016-11/msg00096.html
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1346055
Exploit
https://bugzilla.suse.com/show_bug.cgi?id=984639
Exploit
Analysis
#
Affected Component
Analysis
dovecot
False Positive
Vulnerability Ratings
#
3.3
CVSSv31
2.1
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
dovecot
buildroot
2025.02.x
2.3.21.1
Not Affected
dovecot
buildroot
master
2.3.21.1
Not Affected
dovecot
openwrt
master
2.3.21-r1
Not Affected
dovecot
openwrt
openwrt-25.12
2.3.21-r1
Not Affected
dovecot
yocto
kirkstone
2.3.14
Not Affected
dovecot
yocto
master
2.4.4
False Positive