CVE-2011-2167: Path Traversal
Published May 24, 2011
·Updated
script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
Affected Software
13 affected components
Dovecot dovecot=2.0.9
Dovecot dovecot=2.0.7
Dovecot dovecot=2.0.12
Dovecot dovecot=2.0.4
Dovecot dovecot=2.0.2
Dovecot dovecot=2.0.1
Dovecot dovecot=2.0.10
Dovecot dovecot=2.0.11
Dovecot dovecot=2.0.8
Dovecot dovecot=2.0.3
Dovecot dovecot=2.0.0
Dovecot dovecot=2.0.5
Dovecot dovecot=2.0.6
Remediation
Patch Available
Patch Available
Event History
May 24, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2167?
CVE-2011-2167 is considered a moderate severity vulnerability due to its potential for directory traversal attacks.
2
How do I fix CVE-2011-2167?
To fix CVE-2011-2167, upgrade Dovecot to version 2.0.13 or later.
3
Which versions of Dovecot are affected by CVE-2011-2167?
CVE-2011-2167 affects Dovecot versions 2.0.0 to 2.0.12.
4
What kind of attack can be executed through CVE-2011-2167?
CVE-2011-2167 allows remote authenticated users to conduct directory traversal attacks.
5
Is CVE-2011-2167 related to the chroot configuration in Dovecot?
Yes, CVE-2011-2167 does not follow the chroot configuration setting, leading to potential security risks.