CVE-2010-3779

Publication date 6 October 2010

Last updated 24 July 2024


Ubuntu priority

Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.

Read the notes from the security team

Status

Package Ubuntu Release Status
dovecot 10.10 maverick
Fixed 1:1.2.12-1ubuntu8.1
10.04 LTS lucid
Fixed 1:1.2.9-1ubuntu6.3
9.10 karmic
Not affected
9.04 jaunty Ignored end of life
8.04 LTS hardy
Not affected
6.06 LTS dapper
Not affected

Notes


sbeattie

from upstream email at http://www.dovecot.org/list/dovecot/2010-October/053452.html it sounds like problem was introduced in 1.2.8, so earlier may not be vulnerable.


mdeslaur

Code doesn't seem present in karmic and older

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
dovecot

References

Related Ubuntu Security Notices (USN)

    • USN-1059-1
    • Dovecot vulnerabilities
    • 7 February 2011

Other references