dovecot is vulnerable to access control bypass. A flaw was found in the way Dovecot processed multiple Access Control Lists (ACL) defined for a mailbox. In some cases, Dovecot could fail to apply the more specific ACL entry, possibly resulting in more access being granted to the user than intended.
lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html
marc.info/?l=oss-security&m=128620520732377&w=2
marc.info/?l=oss-security&m=128622064325688&w=2
secunia.com/advisories/43220
www.dovecot.org/list/dovecot/2010-October/053450.html
www.dovecot.org/list/dovecot/2010-October/053451.html
www.dovecot.org/list/dovecot/2010-October/053452.html
www.mandriva.com/security/advisories?name=MDVSA-2010:217
www.redhat.com/support/errata/RHSA-2011-0600.html
www.ubuntu.com/usn/USN-1059-1
www.vupen.com/english/advisories/2010/2572
www.vupen.com/english/advisories/2010/2840
www.vupen.com/english/advisories/2011/0301
access.redhat.com/errata/RHSA-2011:0600
access.redhat.com/security/updates/classification/#moderate