CVE-2007-2231
published 2007-04-25CVE-2007-2231: Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.12%
80.0th percentile
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1.0.rc29-1 (bookworm) | dovecot 1.0.rc29-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot vulnerability
vendor_ubuntu·2007-07-17
CVE-2007-2231 Dovecot vulnerability
Title: Dovecot vulnerability
Summary: Dovecot vulnerability
It was discovered that Dovecot, when configured to use non-system-user
spools and compressed folders, would allow directory traversals in
mailbox names. Remote authenticated users could potentially read email
owned by other users.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
Directory traversal in dovecot with zlib plugin
vendor_redhat·2007-03-28·CVSS 4.3
CVE-2007-2231 [MEDIUM] Directory traversal in dovecot with zlib plugin
Directory traversal in dovecot with zlib plugin
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
Statement: This issue did not affect Red Hat Enterprise Linux prior to version 5.
Debian
CVE-2007-2231: dovecot - Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before...
vendor_debian·2007·CVSS 4.3
CVE-2007-2231 [MEDIUM] CVE-2007-2231: dovecot - Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before...
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
Scope: local
bookworm: resolved (fixed in 1.0.rc29-1)
bullseye: resolved (fixed in 1.0.rc29-1)
forky: resolved (fixed in 1.0.rc29-1)
sid: resolved (fixed in 1.0.rc29-1)
trixie: resolved (fixed in 1.0.rc29-1)
GHSA
GHSA-8qfr-2vxg-8g3g: Directory traversal vulnerability in index/mbox/mbox-storage
ghsa_unreviewed·2022-05-01
CVE-2007-2231 [MEDIUM] GHSA-8qfr-2vxg-8g3g: Directory traversal vulnerability in index/mbox/mbox-storage
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
OSV
CVE-2007-2231: Directory traversal vulnerability in index/mbox/mbox-storage
osv·2007-04-25·CVSS 4.3
CVE-2007-2231 [MEDIUM] CVE-2007-2231: Directory traversal vulnerability in index/mbox/mbox-storage
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2231 Directory traversal in dovecot with zlib plugin
bugzilla·2007-04-30·CVSS 4.3
CVE-2007-2231 [MEDIUM] CVE-2007-2231 Directory traversal in dovecot with zlib plugin
CVE-2007-2231 Directory traversal in dovecot with zlib plugin
+++ This bug was initially created as a clone of Bug #238439 +++
Description of problem:
In case zlib plugin is enabled, dovecot didn't check if mbox path
contained ".." which could be exploited to read compressed mailboxes
of other users.
As the dovecot-news post referred to in URL field states, this is an
unlikely scenario, as it moreover needs the files to be readable by
UID the dovecot is running under after the malicious user logs in.
Version-Release number of selected component (if applicable):
Does not Affect: FC6
Affects: FC5
Affects: RHEL4
Affects: RHEL5
Discussion:
dovecot-1.0-0.beta8.4.fc5 has been pushed for fc5, which should resolve this issue. If these problems are still present in this version, then please
Bugzilla
CVE-2007-2231 Directory traversal in dovecot with zlib plugin
bugzilla·2007-04-30·CVSS 4.3
CVE-2007-2231 [MEDIUM] CVE-2007-2231 Directory traversal in dovecot with zlib plugin
CVE-2007-2231 Directory traversal in dovecot with zlib plugin
Description of problem:
In case zlib plugin is enabled, dovecot didn't check if mbox path
contained ".." which could be exploited to read compressed mailboxes
of other users.
As the dovecot-news post referred to in URL field states, this is an
unlikely scenario, as it moreover needs the files to be readable by
UID the dovecot is running under after the malicious user logs in.
Version-Release number of selected component (if applicable):
Does not Affect: FC6
Affects: FC5
Affects: RHEL4
Affects: RHEL5
Discussion:
Correction to comment #0:
This issue did not affect dovecot packages as shipped in Red Hat Enterprise
Linux 4, as they do not include zlib plugin. Only dovecot in Red Hat Enterprise
Linux 5 was affected.
---
Rep
http://dovecot.org/doc/NEWShttp://dovecot.org/list/dovecot-cvs/2007-March/008488.htmlhttp://dovecot.org/list/dovecot-news/2007-March/000038.htmlhttp://secunia.com/advisories/25072http://secunia.com/advisories/30342http://www.debian.org/security/2007/dsa-1359http://www.novell.com/linux/security/advisories/2007_8_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0297.htmlhttp://www.securityfocus.com/archive/1/466168/100/0/threadedhttp://www.securityfocus.com/bid/23552http://www.ubuntu.com/usn/usn-487-1http://www.vupen.com/english/advisories/2007/1452https://exchange.xforce.ibmcloud.com/vulnerabilities/34082https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10995http://dovecot.org/doc/NEWShttp://dovecot.org/list/dovecot-cvs/2007-March/008488.htmlhttp://dovecot.org/list/dovecot-news/2007-March/000038.htmlhttp://secunia.com/advisories/25072http://secunia.com/advisories/30342http://www.debian.org/security/2007/dsa-1359http://www.novell.com/linux/security/advisories/2007_8_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0297.htmlhttp://www.securityfocus.com/archive/1/466168/100/0/threadedhttp://www.securityfocus.com/bid/23552http://www.ubuntu.com/usn/usn-487-1http://www.vupen.com/english/advisories/2007/1452https://exchange.xforce.ibmcloud.com/vulnerabilities/34082https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10995
2007-04-25
Published