|
|
| |
|
| |
dovecot: restriction bypass/directory traversal
| Package(s): | dovecot |
CVE #(s): | CVE-2011-2166
CVE-2011-2167
|
| Created: | February 21, 2013 |
Updated: | February 27, 2013 |
| Description: |
From the CVE entries:
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script. (CVE-2011-2166)
script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script. (CVE-2011-2167)
|
| Alerts: |
|
( Log in to post comments)
|
|
|