Lucene search

K
ubuntuUbuntuUSN-1059-1
HistoryFeb 07, 2011 - 12:00 a.m.

Dovecot vulnerabilities

2011-02-0700:00:00
ubuntu.com
44

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.009

Percentile

82.6%

Releases

  • Ubuntu 10.10
  • Ubuntu 10.04

Packages

  • dovecot -

Details

It was discovered that the ACL plugin in Dovecot would incorrectly
propagate ACLs to new mailboxes. A remote authenticated user could possibly
read new mailboxes that were created with the wrong ACL. (CVE-2010-3304)

It was discovered that the ACL plugin in Dovecot would incorrectly merge
ACLs in certain circumstances. A remote authenticated user could possibly
bypass intended access restrictions and gain access to mailboxes.
(CVE-2010-3706, CVE-2010-3707)

It was discovered that the ACL plugin in Dovecot would incorrectly grant
the admin permission to owners of certain mailboxes. A remote authenticated
user could possibly bypass intended access restrictions and gain access to
mailboxes. (CVE-2010-3779)

It was discovered that Dovecot incorrecly handled the simultaneous
disconnect of a large number of sessions. A remote authenticated user could
use this flaw to cause Dovecot to crash, resulting in a denial of service.
(CVE-2010-3780)

OSVersionArchitecturePackageVersionFilename
Ubuntu10.10noarchdovecot-common< 1:1.2.12-1ubuntu8.1UNKNOWN
Ubuntu10.10noarchdovecot-dbg< 1:1.2.12-1ubuntu8.1UNKNOWN
Ubuntu10.10noarchdovecot-dev< 1:1.2.12-1ubuntu8.1UNKNOWN
Ubuntu10.10noarchdovecot-imapd< 1:1.2.12-1ubuntu8.1UNKNOWN
Ubuntu10.10noarchdovecot-pop3d< 1:1.2.12-1ubuntu8.1UNKNOWN
Ubuntu10.04noarchdovecot-common< 1:1.2.9-1ubuntu6.3UNKNOWN
Ubuntu10.04noarchdovecot-dbg< 1:1.2.9-1ubuntu6.3UNKNOWN
Ubuntu10.04noarchdovecot-dev< 1:1.2.9-1ubuntu6.3UNKNOWN
Ubuntu10.04noarchdovecot-imapd< 1:1.2.9-1ubuntu6.3UNKNOWN
Ubuntu10.04noarchdovecot-pop3d< 1:1.2.9-1ubuntu6.3UNKNOWN

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.009

Percentile

82.6%