CVE-2010-3304
published 2010-09-24CVE-2010-3304: The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to…
PriorityP432medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.71%
84.4th percentile
The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1.2.13-1 (bookworm) | dovecot 1.2.13-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | >= 0 < 1.2.13-1 | 1.2.13-1 |
| dovecot | dovecot | >= 0 < 1.2.13-1 | 1.2.13-1 |
| dovecot | dovecot | >= 0 < 1.2.13-1 | 1.2.13-1 |
| dovecot | dovecot | >= 0 < 1.2.13-1 | 1.2.13-1 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8j3r-92hg-4567: The ACL plugin in Dovecot 1
ghsa_unreviewed·2022-05-17
CVE-2010-3304 [MEDIUM] GHSA-8j3r-92hg-4567: The ACL plugin in Dovecot 1
The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
OSV
CVE-2010-3304: The ACL plugin in Dovecot 1
osv·2010-09-24·CVSS 6.4
CVE-2010-3304 [MEDIUM] CVE-2010-3304: The ACL plugin in Dovecot 1
The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2011-02-07·CVSS 6.4
CVE-2010-3779 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
It was discovered that the ACL plugin in Dovecot would incorrectly
propagate ACLs to new mailboxes. A remote authenticated user could possibly
read new mailboxes that were created with the wrong ACL. (CVE-2010-3304)
It was discovered that the ACL plugin in Dovecot would incorrectly merge
ACLs in certain circumstances. A remote authenticated user could possibly
bypass intended access restrictions and gain access to mailboxes.
(CVE-2010-3706, CVE-2010-3707)
It was discovered that the ACL plugin in Dovecot would incorrectly grant
the admin permission to owners of certain mailboxes. A remote authenticated
user could possibly bypass intended access restrictions and gain access to
mailboxes. (CVE-2010-3779)
It was discovered that Dovecot incorrecly handled the
Red Hat
dovecot: INBOX ACLs to newly created mailboxes propagation, possibly leading to weak ACLs
vendor_redhat·2010-07-24·CVSS 6.4
CVE-2010-3304 [MEDIUM] dovecot: INBOX ACLs to newly created mailboxes propagation, possibly leading to weak ACLs
dovecot: INBOX ACLs to newly created mailboxes propagation, possibly leading to weak ACLs
The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
Statement: This issue does not affect the version of dovecot package, as shipped with Red Hat Enterprise Linux 4, 5 and 6.
Package: dovecot (Red Hat Enterprise Linux 4) - Not affected
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: dovecot (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-3304: dovecot - The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly cre...
vendor_debian·2010·CVSS 6.4
CVE-2010-3304 [MEDIUM] CVE-2010-3304: dovecot - The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly cre...
The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
Scope: local
bookworm: resolved (fixed in 1.2.13-1)
bullseye: resolved (fixed in 1.2.13-1)
forky: resolved (fixed in 1.2.13-1)
sid: resolved (fixed in 1.2.13-1)
trixie: resolved (fixed in 1.2.13-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot-news/2010-July/000163.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.openwall.com/lists/oss-security/2010/09/16/14http://www.openwall.com/lists/oss-security/2010/09/16/17http://www.securityfocus.com/bid/41964http://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot-news/2010-July/000163.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.openwall.com/lists/oss-security/2010/09/16/14http://www.openwall.com/lists/oss-security/2010/09/16/17http://www.securityfocus.com/bid/41964http://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301
2010-09-24
Published