CVE-2010-3780
published 2010-10-06CVE-2010-3780: Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1)…
PriorityP415medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.35%
81.9th percentile
Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:1.2.15-1 (bookworm) | dovecot 1:1.2.15-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
| dovecot | dovecot | >= 0 < 1:1.2.15-1 | 1:1.2.15-1 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cc69-pg9v-6fx9: Dovecot 1
ghsa_unreviewed·2022-05-17
CVE-2010-3780 [MEDIUM] GHSA-cc69-pg9v-6fx9: Dovecot 1
Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
OSV
CVE-2010-3780: Dovecot 1
osv·2010-10-06·CVSS 4.0
CVE-2010-3780 [MEDIUM] CVE-2010-3780: Dovecot 1
Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2011-02-07·CVSS 6.4
CVE-2010-3779 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
It was discovered that the ACL plugin in Dovecot would incorrectly
propagate ACLs to new mailboxes. A remote authenticated user could possibly
read new mailboxes that were created with the wrong ACL. (CVE-2010-3304)
It was discovered that the ACL plugin in Dovecot would incorrectly merge
ACLs in certain circumstances. A remote authenticated user could possibly
bypass intended access restrictions and gain access to mailboxes.
(CVE-2010-3706, CVE-2010-3707)
It was discovered that the ACL plugin in Dovecot would incorrectly grant
the admin permission to owners of certain mailboxes. A remote authenticated
user could possibly bypass intended access restrictions and gain access to
mailboxes. (CVE-2010-3779)
It was discovered that Dovecot incorrecly handled the
Red Hat
Dovecot: Busy master process, receiving a lot of SIGCHLD signals rapidly while logging, could die
vendor_redhat·2010-10-06·CVSS 4.0
CVE-2010-3780 [MEDIUM] Dovecot: Busy master process, receiving a lot of SIGCHLD signals rapidly while logging, could die
Dovecot: Busy master process, receiving a lot of SIGCHLD signals rapidly while logging, could die
Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
Package: dovecot (Red Hat Enterprise Linux 4) - Not affected
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2010-3780: dovecot - Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial ...
vendor_debian·2010·CVSS 4.0
CVE-2010-3780 [MEDIUM] CVE-2010-3780: dovecot - Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial ...
Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
Scope: local
bookworm: resolved (fixed in 1:1.2.15-1)
bullseye: resolved (fixed in 1:1.2.15-1)
forky: resolved (fixed in 1:1.2.15-1)
sid: resolved (fixed in 1:1.2.15-1)
trixie: resolved (fixed in 1:1.2.15-1)
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot/2010-October/053450.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.redhat.com/support/errata/RHSA-2011-0600.htmlhttp://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301http://secunia.com/advisories/43220http://www.dovecot.org/list/dovecot/2010-October/053450.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:217http://www.redhat.com/support/errata/RHSA-2011-0600.htmlhttp://www.ubuntu.com/usn/USN-1059-1http://www.vupen.com/english/advisories/2010/2840http://www.vupen.com/english/advisories/2011/0301
2010-10-06
Published