CVE-2010-3779: Low severity Dovecot dovecot vulnerability
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3779?
CVE-2010-3779 is considered a medium severity vulnerability.
How do I fix CVE-2010-3779?
To fix CVE-2010-3779, upgrade Dovecot to version 1.2.15 or later for the 1.2.x series or version 2.0.beta2 or later for the 2.0.x series.
Who is affected by CVE-2010-3779?
CVE-2010-3779 affects users of Dovecot versions 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2.
What type of vulnerability is CVE-2010-3779?
CVE-2010-3779 is an access control vulnerability that allows remote authenticated users to bypass intended mailbox access restrictions.
Can CVE-2010-3779 be exploited remotely?
Yes, CVE-2010-3779 can be exploited by remote authenticated users who could change the ACL of a mailbox.