Lucene search

K
nvd[email protected]NVD:CVE-2010-3779
HistoryOct 06, 2010 - 9:00 p.m.

CVE-2010-3779

2010-10-0621:00:01
CWE-264
web.nvd.nist.gov
4

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.002

Percentile

60.8%

Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.

Affected configurations

Nvd
Node
dovecotdovecotMatch1.2.0
OR
dovecotdovecotMatch1.2.1
OR
dovecotdovecotMatch1.2.2
OR
dovecotdovecotMatch1.2.3
OR
dovecotdovecotMatch1.2.4
OR
dovecotdovecotMatch1.2.5
OR
dovecotdovecotMatch1.2.6
OR
dovecotdovecotMatch1.2.7
OR
dovecotdovecotMatch1.2.8
OR
dovecotdovecotMatch1.2.9
OR
dovecotdovecotMatch1.2.10
OR
dovecotdovecotMatch1.2.11
OR
dovecotdovecotMatch1.2.12
OR
dovecotdovecotMatch1.2.13
OR
dovecotdovecotMatch1.2.14
Node
dovecotdovecotMatch2.0beta1
VendorProductVersionCPE
dovecotdovecot1.2.0cpe:2.3:a:dovecot:dovecot:1.2.0:*:*:*:*:*:*:*
dovecotdovecot1.2.1cpe:2.3:a:dovecot:dovecot:1.2.1:*:*:*:*:*:*:*
dovecotdovecot1.2.2cpe:2.3:a:dovecot:dovecot:1.2.2:*:*:*:*:*:*:*
dovecotdovecot1.2.3cpe:2.3:a:dovecot:dovecot:1.2.3:*:*:*:*:*:*:*
dovecotdovecot1.2.4cpe:2.3:a:dovecot:dovecot:1.2.4:*:*:*:*:*:*:*
dovecotdovecot1.2.5cpe:2.3:a:dovecot:dovecot:1.2.5:*:*:*:*:*:*:*
dovecotdovecot1.2.6cpe:2.3:a:dovecot:dovecot:1.2.6:*:*:*:*:*:*:*
dovecotdovecot1.2.7cpe:2.3:a:dovecot:dovecot:1.2.7:*:*:*:*:*:*:*
dovecotdovecot1.2.8cpe:2.3:a:dovecot:dovecot:1.2.8:*:*:*:*:*:*:*
dovecotdovecot1.2.9cpe:2.3:a:dovecot:dovecot:1.2.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.002

Percentile

60.8%