|
|
| |
|
| |
dovecot: multiple vulnerabilities
| Package(s): | dovecot |
CVE #(s): | CVE-2010-3779
CVE-2010-3780
|
| Created: | November 1, 2010 |
Updated: | May 19, 2011 |
| Description: |
From the Mandriva advisory:
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin
permission to the owner of each mailbox in a non-public namespace,
which might allow remote authenticated users to bypass intended access
restrictions by changing the ACL of a mailbox, as demonstrated by a
symlinked shared mailbox (CVE-2010-3779).
Dovecot 1.2.x before 1.2.15 allows remote authenticated users to
cause a denial of service (master process outage) by simultaneously
disconnecting many (1) IMAP or (2) POP3 sessions (CVE-2010-3780).
|
| Alerts: |
|
( Log in to post comments)
|
|
|