CVE-2010-3706
Publication date 6 October 2010
Last updated 24 July 2024
Ubuntu priority
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
Status
Package | Ubuntu Release | Status |
---|---|---|
dovecot | ||
Notes
Patch details
Package | Patch details |
---|---|
dovecot |
References
Related Ubuntu Security Notices (USN)
- USN-1059-1
- Dovecot vulnerabilities
- 7 February 2011