CVE-2011-2167Path Traversal in Dovecot

CWE-22Path Traversal7 documents6 sources
Severity
6.5MEDIUMNVD
EPSS
0.4%
top 37.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 24
Latest updateMay 17

Description

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/dovecot< dovecot 1:2.0.13-1 (bookworm)
Debiandovecot/dovecot< 1:2.0.13-1+3
NVDdovecot/dovecot13 versions+12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w278-mxj8-7r9j: script-login in Dovecot 22022-05-17
OSV
CVE-2011-2167: script-login in Dovecot 22011-05-24

📋Vendor Advisories

2
Red Hat
dovecot: directory traversal due to not obeying chroot directive2011-05-11
Debian
CVE-2011-2167: dovecot - script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configura...2011

💬Community

2
Bugzilla
CVE-2011-1929 CVE-2011-2166 CVE-2011-2167 dovecot various flaws [fedora-all]2011-05-30
Bugzilla
CVE-2011-2167 dovecot: directory traversal due to not obeying chroot directive2011-05-30