CVE-2010-3707
Summary
| CVE | CVE-2010-3707 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-10-06 17:00:17 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dovecot | Dovecot | 1.2.0 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.1 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.10 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.11 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.12 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.13 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.14 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.2 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.3 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.4 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.5 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.6 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.7 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.8 | All | All | All |
| Application | Dovecot | Dovecot | 1.2.9 | All | All | All |
| Application | Dovecot | Dovecot | 2.0.0 | All | All | All |
| Application | Dovecot | Dovecot | 2.0.1 | All | All | All |
| Application | Dovecot | Dovecot | 2.0.2 | All | All | All |
| Application | Dovecot | Dovecot | 2.0.3 | All | All | All |
| Application | Dovecot | Dovecot | 2.0.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support / Security / Advisories / / MDVSA-2010:217 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [Dovecot] v2.0.5 released | af854a3a-2127-422b-91ae-364da2661108 | www.dovecot.org | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| [Dovecot] v1.2.15 released | af854a3a-2127-422b-91ae-364da2661108 | www.dovecot.org | Vendor Advisory |
| USN-1059-1: Dovecot vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:020 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Ubuntu update for dovecot - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [Dovecot] ACL handling bugs in v1.2.8+ and v2.0 | af854a3a-2127-422b-91ae-364da2661108 | www.dovecot.org | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| 'Re: [oss-security] CVE Request: more dovecot ACL issues' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| '[oss-security] CVE Request: more dovecot ACL issues' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.