CVE-2007-4211
published 2007-08-08CVE-2007-4211: The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
PriorityP424medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.38%
69.2th percentile
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:1.0.3-2 (bookworm) | dovecot 1:1.0.3-2 (bookworm) |
| dovecot | dovecot | <= 1.0.2 | — |
| dovecot | dovecot | >= 0 < 1:1.0.3-2 | 1:1.0.3-2 |
| dovecot | dovecot | >= 0 < 1:1.0.3-2 | 1:1.0.3-2 |
| dovecot | dovecot | >= 0 < 1:1.0.3-2 | 1:1.0.3-2 |
| dovecot | dovecot | >= 0 < 1:1.0.3-2 | 1:1.0.3-2 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0LOW
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Dovecot possible privilege ascalation in ACL plugin
vendor_redhat·2007-08-01·CVSS 6.0
CVE-2007-4211 [MEDIUM] Dovecot possible privilege ascalation in ACL plugin
Dovecot possible privilege ascalation in ACL plugin
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
Statement: These issues did not affect the dovecot versions as shipped with Red Hat Enterprise Linux 2.1, 3, or 4.
Debian
CVE-2007-4211: dovecot - The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with th...
vendor_debian·2007·CVSS 6.0
CVE-2007-4211 [MEDIUM] CVE-2007-4211: dovecot - The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with th...
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
Scope: local
bookworm: resolved (fixed in 1:1.0.3-2)
bullseye: resolved (fixed in 1:1.0.3-2)
forky: resolved (fixed in 1:1.0.3-2)
sid: resolved (fixed in 1:1.0.3-2)
trixie: resolved (fixed in 1:1.0.3-2)
GHSA
GHSA-7qph-c6xr-695q: The ACL plugin in Dovecot before 1
ghsa_unreviewed·2022-05-01
CVE-2007-4211 [MEDIUM] GHSA-7qph-c6xr-695q: The ACL plugin in Dovecot before 1
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
OSV
CVE-2007-4211: The ACL plugin in Dovecot before 1
osv·2007-08-08·CVSS 6.0
CVE-2007-4211 [MEDIUM] CVE-2007-4211: The ACL plugin in Dovecot before 1
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin [F7]
bugzilla·2007-08-06·CVSS 6.0
CVE-2007-4211 [MEDIUM] CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin [F7]
CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
dovecot-1.0.3-14.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin
bugzilla·2007-08-06·CVSS 6.0
CVE-2007-4211 [MEDIUM] CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin
CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin
Description of problem:
A new version of dovecot was issued, The announcement (see URL) reads:
- ACL plugin: If user was given i (insert) right for a mailbox, but
not all s/t/w (seen, deleted, other flags) rights, COPY and APPEND
commands weren't supposed to allow saving those flags. This is
technically a security fix, but it's unlikely this caused problems
for anyone.
Version-Release number of selected component (if applicable):
Affects: FC7
Affects: FC6
Affects: RHEL5
Doesn't Affect: RHEL4 (no ACL plugin)
Doesn't Affect: RHEL3 (dovecot not shipped)
Doesn't Affect: RHEL2.1 (dovecot not shipped)
Discussion:
Upstream fixed in 1.0.3:
http://www.dovecot.org/list/dovecot-news/2007-August/000048.html
All current Fedora ve
Bugzilla
CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin [FC6]
bugzilla·2007-08-06·CVSS 6.0
CVE-2007-4211 [MEDIUM] CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin [FC6]
CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
http://secunia.com/advisories/26320http://secunia.com/advisories/26475http://secunia.com/advisories/30342http://www.dovecot.org/list/dovecot-news/2007-August/000048.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0297.htmlhttp://www.securityfocus.com/bid/25182https://exchange.xforce.ibmcloud.com/vulnerabilities/35767https://issues.rpath.com/browse/RPL-1621https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11558http://secunia.com/advisories/26320http://secunia.com/advisories/26475http://secunia.com/advisories/30342http://www.dovecot.org/list/dovecot-news/2007-August/000048.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0297.htmlhttp://www.securityfocus.com/bid/25182https://exchange.xforce.ibmcloud.com/vulnerabilities/35767https://issues.rpath.com/browse/RPL-1621https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11558
2007-08-08
Published