CVE-2010-3707

high

Description

plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.

References

http://www.vupen.com/english/advisories/2011/0301

http://www.vupen.com/english/advisories/2010/2840

http://www.vupen.com/english/advisories/2010/2572

http://www.ubuntu.com/usn/USN-1059-1

http://www.redhat.com/support/errata/RHSA-2011-0600.html

http://www.mandriva.com/security/advisories?name=MDVSA-2010:217

http://www.dovecot.org/list/dovecot/2010-October/053452.html

http://www.dovecot.org/list/dovecot/2010-October/053451.html

http://www.dovecot.org/list/dovecot/2010-October/053450.html

http://secunia.com/advisories/43220

http://marc.info/?l=oss-security&m=128622064325688&w=2

http://marc.info/?l=oss-security&m=128620520732377&w=2

http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html

Details

Source: Mitre, NVD

Published: 2010-10-06

Updated: 2011-08-27

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High