CVE-2010-3706
published 2010-10-06CVE-2010-3706: plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted…
PriorityP427medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
2.13%
80.0th percentile
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:1.2.15-1 (bookworm) | dovecot 1:1.2.15-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv5.5MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2011-02-07·CVSS 6.4
CVE-2010-3779 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
It was discovered that the ACL plugin in Dovecot would incorrectly
propagate ACLs to new mailboxes. A remote authenticated user could possibly
read new mailboxes that were created with the wrong ACL. (CVE-2010-3304)
It was discovered that the ACL plugin in Dovecot would incorrectly merge
ACLs in certain circumstances. A remote authenticated user could possibly
bypass intended access restrictions and gain access to mailboxes.
(CVE-2010-3706, CVE-2010-3707)
It was discovered that the ACL plugin in Dovecot would incorrectly grant
the admin permission to owners of certain mailboxes. A remote authenticated
user could possibly bypass intended access restrictions and gain access to
mailboxes. (CVE-2010-3779)
It was discovered that Dovecot incorrecly handled the
Red Hat
Dovecot: Failed to update ACL cache for mailboxes stored in private namespace
vendor_redhat·2010-10-01·CVSS 5.5
CVE-2010-3706 [MEDIUM] Dovecot: Failed to update ACL cache for mailboxes stored in private namespace
Dovecot: Failed to update ACL cache for mailboxes stored in private namespace
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
Statement: Not vulnerable. This issue did not affect the versions of dovecot as
shipped with Red Hat Enterprise Linux 4, 5 or 6.
Package: dovecot (Red Hat Enterprise Linux 4) - Not affected
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: doveco
Debian
CVE-2010-3706: dovecot - plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before ...
vendor_debian·2010·CVSS 5.5
CVE-2010-3706 [MEDIUM] CVE-2010-3706: dovecot - plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before ...
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
Scope: local
bookworm: resolved (fixed in 1:1.2.15-1)
bullseye: resolved (fixed in 1:1.2.15-1)
forky: resolved (fixed in 1:1.2.15-1)
sid: resolved (fixed in 1:1.2.15-1)
trixie: resolved (fixed in 1:1.2.15-1)
GHSA
GHSA-6g2j-hjvm-jvwm: plugins/acl/acl-backend-vfile
ghsa_unreviewed·2022-05-17
CVE-2010-3706 [MEDIUM] GHSA-6g2j-hjvm-jvwm: plugins/acl/acl-backend-vfile
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
OSV
CVE-2010-3706: plugins/acl/acl-backend-vfile
osv·2010-10-06·CVSS 5.5
CVE-2010-3706 [MEDIUM] CVE-2010-3706: plugins/acl/acl-backend-vfile
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.htmlhttp://marc.info/?l=oss-security&m=128620520732377&w=2http://marc.info/?l=oss-security&m=128622064325688&w=2http://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot/2010-October/053450.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053451.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053452.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2572http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.htmlhttp://marc.info/?l=oss-security&m=128620520732377&w=2http://marc.info/?l=oss-security&m=128622064325688&w=2http://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot/2010-October/053450.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053451.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053452.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2572http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301
2010-10-06
Published