CVE-2010-3707
published 2010-10-06CVE-2010-3707: plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted…
PriorityP427medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
2.67%
84.2th percentile
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:1.2.15-1 (bookworm) | dovecot 1:1.2.15-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv5.5MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2011-02-07·CVSS 6.4
CVE-2010-3779 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
It was discovered that the ACL plugin in Dovecot would incorrectly
propagate ACLs to new mailboxes. A remote authenticated user could possibly
read new mailboxes that were created with the wrong ACL. (CVE-2010-3304)
It was discovered that the ACL plugin in Dovecot would incorrectly merge
ACLs in certain circumstances. A remote authenticated user could possibly
bypass intended access restrictions and gain access to mailboxes.
(CVE-2010-3706, CVE-2010-3707)
It was discovered that the ACL plugin in Dovecot would incorrectly grant
the admin permission to owners of certain mailboxes. A remote authenticated
user could possibly bypass intended access restrictions and gain access to
mailboxes. (CVE-2010-3779)
It was discovered that Dovecot incorrecly handled the
Red Hat
Dovecot: Failed to properly update ACL cache, when multiple rules defined rights for one subject
vendor_redhat·2010-10-01·CVSS 5.5
CVE-2010-3707 [MEDIUM] Dovecot: Failed to properly update ACL cache, when multiple rules defined rights for one subject
Dovecot: Failed to properly update ACL cache, when multiple rules defined rights for one subject
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
Statement: This issue did not affect the version of dovecot package, as shipped with Red
Hat Enterprise Linux 4 and 5. This issue affects the version of dovecot
package as shipped with Red Hat Enterprise Linux 6. The Red
Debian
CVE-2010-3707: dovecot - plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before ...
vendor_debian·2010·CVSS 5.5
CVE-2010-3707 [MEDIUM] CVE-2010-3707: dovecot - plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before ...
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
Scope: local
bookworm: resolved (fixed in 1:1.2.15-1)
bullseye: resolved (fixed in 1:1.2.15-1)
forky: resolved (fixed in 1:1.2.15-1)
sid: resolved (fixed in 1:1.2.15-1)
trixie: resolved (fixed in 1:1.2.15-1)
GHSA
GHSA-px5f-9v9f-4cpw: plugins/acl/acl-backend-vfile
ghsa_unreviewed·2022-05-17
CVE-2010-3707 [MEDIUM] GHSA-px5f-9v9f-4cpw: plugins/acl/acl-backend-vfile
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
OSV
CVE-2010-3707: plugins/acl/acl-backend-vfile
osv·2010-10-06·CVSS 5.5
CVE-2010-3707 [MEDIUM] CVE-2010-3707: plugins/acl/acl-backend-vfile
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.htmlhttp://marc.info/?l=oss-security&m=128620520732377&w=2http://marc.info/?l=oss-security&m=128622064325688&w=2http://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot/2010-October/053450.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053451.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053452.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.redhat.com/support/errata/RHSA-2011-0600.htmlhttp://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2572http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.htmlhttp://marc.info/?l=oss-security&m=128620520732377&w=2http://marc.info/?l=oss-security&m=128622064325688&w=2http://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot/2010-October/053450.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053451.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053452.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.redhat.com/support/errata/RHSA-2011-0600.htmlhttp://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2572http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301
2010-10-06
Published