Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-3779
HistoryOct 06, 2010 - 12:00 a.m.

CVE-2010-3779

2010-10-0600:00:00
ubuntu.com
ubuntu.com
13

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

60.8%

Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin
permission to the owner of each mailbox in a non-public namespace, which
might allow remote authenticated users to bypass intended access
restrictions by changing the ACL of a mailbox, as demonstrated by a
symlinked shared mailbox.

Bugs

Notes

Author Note
sbeattie from upstream email at http://www.dovecot.org/list/dovecot/2010-October/053452.html it sounds like problem was introduced in 1.2.8, so earlier may not be vulnerable.
mdeslaur Code doesn’t seem present in karmic and older
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchdovecot< 1:1.2.9-1ubuntu6.3UNKNOWN
ubuntu10.10noarchdovecot< 1:1.2.12-1ubuntu8.1UNKNOWN

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

60.8%