cbcvebase.
CVE-2010-3779
published 2010-10-06

CVE-2010-3779: Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow…

PriorityP412low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.10%
62.1th percentile
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:1.2.15-1 (bookworm)dovecot 1:1.2.15-1 (bookworm)
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot>= 0 < 1:1.2.15-11:1.2.15-1
dovecotdovecot>= 0 < 1:1.2.15-11:1.2.15-1
dovecotdovecot>= 0 < 1:1.2.15-11:1.2.15-1
dovecotdovecot>= 0 < 1:1.2.15-11:1.2.15-1

CVSS provenance

nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_ubuntu6.4MEDIUM
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.