LWN.net Logo

dovecot: multiple vulnerabilities

Package(s):dovecot CVE #(s):CVE-2010-3779 CVE-2010-3780
Created:November 1, 2010 Updated:May 19, 2011
Description: From the Mandriva advisory:

Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox (CVE-2010-3779).

Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions (CVE-2010-3780).

Alerts:
Gentoo 201110-04 2011-10-10
Ubuntu USN-1059-1 2011-02-07
Red Hat RHSA-2011:0600-01 2011-05-19
Mandriva MDVSA-2010:217 2010-10-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds