LWN.net Logo

dovecot: restriction bypass/directory traversal

Package(s):dovecot CVE #(s):CVE-2011-2166 CVE-2011-2167
Created:February 21, 2013 Updated:February 27, 2013
Description: From the CVE entries:

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script. (CVE-2011-2166)

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script. (CVE-2011-2167)

Alerts:
Red Hat RHSA-2013:0520-02 2013-02-21
Oracle ELSA-2013-0520 2013-02-25
Scientific Linux SL-dove-20130304 2013-03-04
CentOS CESA-2013:0520 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds