CVE-2010-4011
published 2010-11-17CVE-2010-4011: Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of…
PriorityP416medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
0.89%
55.7th percentile
Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x_server | — | — |
| debian | dovecot | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_debian4.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-4011: dovecot - Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user...
vendor_debian·2010·CVSS 4.0
CVE-2010-4011 [MEDIUM] CVE-2010-4011: dovecot - Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user...
Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-7mf7-jpv7-pq9x: Dovecot in Apple Mac OS X 10
ghsa_unreviewed·2022-05-17
CVE-2010-4011 [MEDIUM] CWE-200 GHSA-7mf7-jpv7-pq9x: Dovecot in Apple Mac OS X 10
Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2010-11-17
Published