Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2010-3779

Published: 6 October 2010

Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.

Notes

AuthorNote
sbeattie
from upstream email at
http://www.dovecot.org/list/dovecot/2010-October/053452.html it
sounds like problem was introduced in 1.2.8, so earlier may not
be vulnerable.
mdeslaur
Code doesn't seem present in karmic and older

Priority

Low

Status

Package Release Status
dovecot
Launchpad, Ubuntu, Debian
dapper Not vulnerable
(1.0.beta3-3ubuntu5.6)
hardy Not vulnerable
(1:1.0.10-1ubuntu5.2)
jaunty Ignored
(end of life)
karmic Not vulnerable
(1:1.1.11-0ubuntu11)
lucid
Released (1:1.2.9-1ubuntu6.3)
maverick
Released (1:1.2.12-1ubuntu8.1)
upstream
Released (1.2.15, 2.0.5)
Patches:
upstream: http://hg.dovecot.org/dovecot-1.2/rev/9e824012da57