script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade dovecot-pigeonholeUpgrade dovecotUpgrade dovecot-pgsqlUpgrade dovecot-develUpgrade dovecot-mysql | Dec 1, 2016 | May 24, 2011 |
| Debian | — | Upgrade dovecot | Jul 30, 2024 | May 24, 2011 |
| Gentoo Linux | — | Upgrade net-mail/dovecot. | Oct 30, 2017 | May 24, 2011 |
| Oracle_linux | — | Upgrade dovecot-pigeonholeUpgrade dovecot-mysqlUpgrade dovecotUpgrade dovecot-develUpgrade dovecot-pgsql | Oct 16, 2024 | May 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub