5.5
CVSSv2

CVE-2010-3707

Published: 06/10/2010 Updated: 27/08/2011
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x prior to 1.2.15 and 2.0.x prior to 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot 1.2.1

dovecot dovecot 1.2.2

dovecot dovecot 1.2.9

dovecot dovecot 1.2.10

dovecot dovecot 1.2.11

dovecot dovecot 1.2.0

dovecot dovecot 1.2.7

dovecot dovecot 1.2.8

dovecot dovecot 1.2.5

dovecot dovecot 1.2.6

dovecot dovecot 1.2.14

dovecot dovecot 1.2.3

dovecot dovecot 1.2.4

dovecot dovecot 1.2.12

dovecot dovecot 1.2.13

dovecot dovecot 2.0.2

dovecot dovecot 2.0.1

dovecot dovecot 2.0.4

dovecot dovecot 2.0.3

dovecot dovecot 2.0.0

Vendor Advisories

It was discovered that the ACL plugin in Dovecot would incorrectly propagate ACLs to new mailboxes A remote authenticated user could possibly read new mailboxes that were created with the wrong ACL (CVE-2010-3304) ...