cbcvebase.
CVE-2010-3706
published 2010-10-06

CVE-2010-3706: plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted…

PriorityP427medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
2.13%
80.0th percentile
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:1.2.15-1 (bookworm)dovecot 1:1.2.15-1 (bookworm)
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot>= 0 < 1:1.2.15-11:1.2.15-1
dovecotdovecot>= 0 < 1:1.2.15-11:1.2.15-1
dovecotdovecot>= 0 < 1:1.2.15-11:1.2.15-1
dovecotdovecot>= 0 < 1:1.2.15-11:1.2.15-1

CVSS provenance

nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv5.5MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.