LWN.net Logo

dovecot: information disclosure

Package(s):dovecot CVE #(s):CVE-2006-2414
Created:May 31, 2006 Updated:June 14, 2006
Description: The Dovecot imap server contains a directory traversal vulnerability which could be exploited by authenticated users to read files other than their mailboxes.
Alerts:
Ubuntu USN-288-4 2006-06-13
Debian DSA-1080-1 2006-05-29

(Log in to post comments)

dovecot: information disclosure

Posted Jun 8, 2006 8:11 UTC (Thu) by cras (guest, #7000) [Link]

Actually "see" would be more correct word than "read" in here, since only the filenames can be seen, not their contents.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds