cbcvebase.
CVE-2007-4211
published 2007-08-08

CVE-2007-4211: The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.

PriorityP424medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.38%
69.2th percentile
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:1.0.3-2 (bookworm)dovecot 1:1.0.3-2 (bookworm)
dovecotdovecot<= 1.0.2
dovecotdovecot>= 0 < 1:1.0.3-21:1.0.3-2
dovecotdovecot>= 0 < 1:1.0.3-21:1.0.3-2
dovecotdovecot>= 0 < 1:1.0.3-21:1.0.3-2
dovecotdovecot>= 0 < 1:1.0.3-21:1.0.3-2

CVSS provenance

nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0LOW
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.