Description
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4 Affected Packages3 packages
🔴Vulnerability Details
2GHSAGHSA-7qph-c6xr-695q: The ACL plugin in Dovecot before 1↗2022-05-01 ▶ OSVCVE-2007-4211: The ACL plugin in Dovecot before 1↗2007-08-08 ▶ 📋Vendor Advisories
2Red HatDovecot possible privilege ascalation in ACL plugin↗2007-08-01 ▶ DebianCVE-2007-4211: dovecot - The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with th...↗2007 ▶ 💬Community
3BugzillaCVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin [F7]↗2007-08-06 ▶ BugzillaCVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin↗2007-08-06 ▶ BugzillaCVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin [FC6]↗2007-08-06 ▶