CVE-2010-3304
Publication date 24 September 2010
Last updated 24 July 2024
Ubuntu priority
The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
Status
Package | Ubuntu Release | Status |
---|---|---|
dovecot | ||
Notes
mdeslaur
upstream says only 1.2.x, but code is present in at least as far back as jaunty. Code doesn't look affected in hardy and earlier. Couldn't reproduce on karmic, so not-affected.
Patch details
Package | Patch details |
---|---|
dovecot |
References
Related Ubuntu Security Notices (USN)
- USN-1059-1
- Dovecot vulnerabilities
- 7 February 2011