First published: Tue May 16 2006(Updated: )
Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dovecot | =1.0_beta7 | |
Dovecot | =1.0_beta2 | |
Dovecot | =1.0 | |
Dovecot | =1.0_beta3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2414 is considered to have a high severity due to its ability to allow remote attackers to list files and directories.
To fix CVE-2006-2414, upgrade to a patched version of Dovecot that addresses this directory traversal vulnerability.
CVE-2006-2414 affects Dovecot versions 1.0 beta2, 1.0 beta3, 1.0 beta7, and 1.0.
Yes, CVE-2006-2414 can allow unauthorized access to mailbox names and potentially sensitive files in the mbox parent directory.
CVE-2006-2414 can be exploited through the LIST and DELETE IMAP commands to perform directory traversal attacks.