Vulnerability Name: | CVE-2010-3304 (CCN-60639) | ||||||||||||
Assigned: | 2010-07-24 | ||||||||||||
Published: | 2010-07-24 | ||||||||||||
Updated: | 2011-02-12 | ||||||||||||
Summary: | The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||
Vulnerability Consequences: | Other | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-3304 Source: SUSE Type: UNKNOWN SUSE-SR:2010:017 Source: CCN Type: SA40723 Dovecot ACL Plugin Maildir / INBOX ACL Weakness Source: SECUNIA Type: UNKNOWN 43220 Source: CCN Type: Dovecot Web Site [Dovecot-news] v1.2.13 released Source: MLIST Type: Patch, Vendor Advisory [dovecot-news] 20100724 v1.2.13 released Source: MANDRIVA Type: UNKNOWN MDVSA-2010:217 Source: MLIST Type: UNKNOWN [oss-security] 20100916 CVE-identifier request for Dovecot ACL security bug Source: MLIST Type: UNKNOWN [oss-security] 20100916 Re: CVE-identifier request for Dovecot ACL security bug Source: CCN Type: OSVDB ID: 66625 Dovecot ACL Plugin INBOX ACL Copying Weakness Restriction Bypass Source: BID Type: UNKNOWN 41964 Source: CCN Type: BID-41964 Dovecot Access Control List (ACL) Plugin Security Bypass Weakness Source: UBUNTU Type: UNKNOWN USN-1059-1 Source: VUPEN Type: UNKNOWN ADV-2010-2840 Source: VUPEN Type: UNKNOWN ADV-2011-0301 Source: XF Type: UNKNOWN dovecot-aclplugin-weak-security(60639) Source: SUSE Type: SUSE-SR:2010:017 (java-1_4_2-ibm, sudo, libpng, php5, tgt, iscsitarget, aria2, pcsc-lite, tomcat5, tomcat6, lvm2, libvirt, rpm, libtiff, dovecot12) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |