CVE Vulnerabilities

CVE-2010-3304

Published: Sep 24, 2010 | Modified: Feb 12, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.

Affected Software

Name Vendor Start Version End Version
Dovecot Dovecot 1.2.0 (including) 1.2.0 (including)
Dovecot Dovecot 1.2.1 (including) 1.2.1 (including)
Dovecot Dovecot 1.2.2 (including) 1.2.2 (including)
Dovecot Dovecot 1.2.3 (including) 1.2.3 (including)
Dovecot Dovecot 1.2.4 (including) 1.2.4 (including)
Dovecot Dovecot 1.2.5 (including) 1.2.5 (including)
Dovecot Dovecot 1.2.6 (including) 1.2.6 (including)
Dovecot Dovecot 1.2.7 (including) 1.2.7 (including)
Dovecot Dovecot 1.2.8 (including) 1.2.8 (including)
Dovecot Dovecot 1.2.9 (including) 1.2.9 (including)
Dovecot Dovecot 1.2.10 (including) 1.2.10 (including)
Dovecot Dovecot 1.2.11 (including) 1.2.11 (including)
Dovecot Dovecot 1.2.12 (including) 1.2.12 (including)
Dovecot Ubuntu jaunty *
Dovecot Ubuntu lucid *
Dovecot Ubuntu maverick *
Dovecot Ubuntu upstream *

References