Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dovecot | Jul 30, 2024 | Apr 25, 2007 |
| Oracle_linux | — | Upgrade dovecot | Oct 16, 2024 | Apr 25, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade dovecot | Feb 17, 2015 | Apr 25, 2007 |
| Ubuntu | — | Upgrade dovecot-common | Nov 8, 2024 | Apr 25, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub