plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dovecot | Jul 30, 2024 | Oct 6, 2010 |
| Gentoo Linux | — | Upgrade net-mail/dovecot. | Oct 30, 2017 | Oct 6, 2010 |
| Suse | — | Upgrade dovecot12-fts-luceneUpgrade dovecot12-backend-pgsqlUpgrade dovecot12-develUpgrade dovecot12-fts-solrUpgrade dovecot12-backend-sqliteUpgrade dovecot12Upgrade dovecot12-backend-mysql | Feb 17, 2015 | Oct 6, 2010 |
| Ubuntu | — | Upgrade dovecot-common | Nov 8, 2024 | Oct 6, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub