4.3
CVSSv2

CVE-2007-2231

Published: 25/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot prior to 1.0.rc29, when using the zlib plugin, allows remote malicious users to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot 1.0.beta4

dovecot dovecot 1.0.beta5

dovecot dovecot 1.0.rc11

dovecot dovecot 1.0.rc12

dovecot dovecot 1.0.rc2

dovecot dovecot 1.0.rc20

dovecot dovecot 1.0.rc27

dovecot dovecot 1.0.rc28

dovecot dovecot 1.0.rc9

dovecot dovecot 1.0.beta2

dovecot dovecot 1.0.beta3

dovecot dovecot 1.0.rc1

dovecot dovecot 1.0.rc10

dovecot dovecot 1.0.rc18

dovecot dovecot 1.0.rc19

dovecot dovecot 1.0.rc25

dovecot dovecot 1.0.rc26

dovecot dovecot 1.0.rc7

dovecot dovecot 1.0.rc8

dovecot dovecot 1.0.beta6

dovecot dovecot 1.0.beta7

dovecot dovecot 1.0.rc13

dovecot dovecot 1.0.rc14

dovecot dovecot 1.0.rc15

dovecot dovecot 1.0.rc21

dovecot dovecot 1.0.rc22

dovecot dovecot 1.0.rc3

dovecot dovecot 1.0.rc4

dovecot dovecot 1.0.beta1

dovecot dovecot 1.0.beta8

dovecot dovecot 1.0.beta9

dovecot dovecot 1.0.rc16

dovecot dovecot 1.0.rc17

dovecot dovecot 1.0.rc23

dovecot dovecot 1.0.rc24

dovecot dovecot 1.0.rc5

dovecot dovecot 1.0.rc6

Vendor Advisories

It was discovered that Dovecot, when configured to use non-system-user spools and compressed folders, would allow directory traversals in mailbox names Remote authenticated users could potentially read email owned by other users ...
It was discovered that dovecot, a secure mail server that supports mbox and maildir mailboxes, when configured to use non-system-user spools and compressed folders, may allow directory traversal in mailbox names For the old stable distribution (sarge), this problem was not present For the stable distribution (etch), this problem has been fixed in ...