CVE-2010-3779
Published: 6 October 2010
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
Notes
Author | Note |
---|---|
sbeattie | from upstream email at http://www.dovecot.org/list/dovecot/2010-October/053452.html it sounds like problem was introduced in 1.2.8, so earlier may not be vulnerable. |
mdeslaur | Code doesn't seem present in karmic and older |
Priority
Status
Package | Release | Status |
---|---|---|
dovecot Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
(1.0.beta3-3ubuntu5.6)
|
hardy |
Not vulnerable
(1:1.0.10-1ubuntu5.2)
|
|
jaunty |
Ignored
(end of life)
|
|
karmic |
Not vulnerable
(1:1.1.11-0ubuntu11)
|
|
lucid |
Released
(1:1.2.9-1ubuntu6.3)
|
|
maverick |
Released
(1:1.2.12-1ubuntu8.1)
|
|
upstream |
Released
(1.2.15, 2.0.5)
|
|
Patches: upstream: http://hg.dovecot.org/dovecot-1.2/rev/9e824012da57 |