CVE-2010-3779
published 2010-10-06CVE-2010-3779: Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow…
PriorityP412low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.10%
62.1th percentile
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:1.2.15-1 (bookworm) | dovecot 1:1.2.15-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_ubuntu6.4MEDIUM
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2011-02-07·CVSS 6.4
CVE-2010-3779 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
It was discovered that the ACL plugin in Dovecot would incorrectly
propagate ACLs to new mailboxes. A remote authenticated user could possibly
read new mailboxes that were created with the wrong ACL. (CVE-2010-3304)
It was discovered that the ACL plugin in Dovecot would incorrectly merge
ACLs in certain circumstances. A remote authenticated user could possibly
bypass intended access restrictions and gain access to mailboxes.
(CVE-2010-3706, CVE-2010-3707)
It was discovered that the ACL plugin in Dovecot would incorrectly grant
the admin permission to owners of certain mailboxes. A remote authenticated
user could possibly bypass intended access restrictions and gain access to
mailboxes. (CVE-2010-3779)
It was discovered that Dovecot incorrecly handled the
Red Hat
Dovecot: Admin permissions granted to the owner of each mailbox in a non-public namespace
vendor_redhat·2010-10-06·CVSS 3.5
CVE-2010-3779 [LOW] Dovecot: Admin permissions granted to the owner of each mailbox in a non-public namespace
Dovecot: Admin permissions granted to the owner of each mailbox in a non-public namespace
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
Statement: Not vulnerable. This issue did not affect the versions of dovecot as
shipped with Red Hat Enterprise Linux 4, 5 or 6.
Package: dovecot (Red Hat Enterprise Linux 4) - Not affected
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: dovecot (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-3779: dovecot - Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permissi...
vendor_debian·2010·CVSS 3.5
CVE-2010-3779 [LOW] CVE-2010-3779: dovecot - Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permissi...
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
Scope: local
bookworm: resolved (fixed in 1:1.2.15-1)
bullseye: resolved (fixed in 1:1.2.15-1)
forky: resolved (fixed in 1:1.2.15-1)
sid: resolved (fixed in 1:1.2.15-1)
trixie: resolved (fixed in 1:1.2.15-1)
GHSA
GHSA-83v9-j2gr-cch4: Dovecot 1
ghsa_unreviewed·2022-05-17
CVE-2010-3779 [LOW] GHSA-83v9-j2gr-cch4: Dovecot 1
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
OSV
CVE-2010-3779: Dovecot 1
osv·2010-10-06·CVSS 3.5
CVE-2010-3779 [LOW] CVE-2010-3779: Dovecot 1
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot/2010-October/053450.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053452.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301http://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot/2010-October/053450.htmlhttp://www.dovecot.org/list/dovecot/2010-October/053452.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301
2010-10-06
Published