CVE-2010-3706: Medium severity Dovecot dovecot vulnerability
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3706?
CVE-2010-3706 has a moderate severity rating due to the potential for privilege escalation in Dovecot.
How do I fix CVE-2010-3706?
To fix CVE-2010-3706, update Dovecot to version 1.2.15 or later, or 2.0.5 or later.
Which versions of Dovecot are affected by CVE-2010-3706?
CVE-2010-3706 affects Dovecot versions 1.2.0 through 1.2.14 and 2.0.0 through 2.0.4.
What kind of vulnerability is CVE-2010-3706?
CVE-2010-3706 is a vulnerability related to Access Control Lists (ACL) mismanagement.
Is it safe to use Dovecot versions before 1.2.15 due to CVE-2010-3706?
Using Dovecot versions before 1.2.15 is not safe as they are vulnerable to CVE-2010-3706.