6.4
CVSSv2

CVE-2010-3304

Published: 24/09/2010 Updated: 12/02/2011
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The ACL plugin in Dovecot 1.2.x prior to 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote malicious users to read mailboxes that have unintended weak ACLs.

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot 1.2.2

dovecot dovecot 1.2.3

dovecot dovecot 1.2.12

dovecot dovecot 1.2.10

dovecot dovecot 1.2.11

dovecot dovecot 1.2.8

dovecot dovecot 1.2.9

dovecot dovecot 1.2.4

dovecot dovecot 1.2.5

dovecot dovecot 1.2.0

dovecot dovecot 1.2.1

dovecot dovecot 1.2.6

dovecot dovecot 1.2.7

Vendor Advisories

It was discovered that the ACL plugin in Dovecot would incorrectly propagate ACLs to new mailboxes A remote authenticated user could possibly read new mailboxes that were created with the wrong ACL (CVE-2010-3304) ...