- Description
- Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
- Hype score
- Not currently trending
- Red HatNot vulnerable. This issue does not affect the versions of Dovecot distributed with Red Hat Enterprise Linux.
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:timo_sirainen:dovecot:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE001666-8419-4F23-A9C4-CC2E929C7447"
},
{
"criteria": "cpe:2.3:a:timo_sirainen:dovecot:1.0_beta2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6C2CA41-C59A-4072-BFAF-1B6D831233D7"
},
{
"criteria": "cpe:2.3:a:timo_sirainen:dovecot:1.0_beta3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0EA25732-C560-4A78-8AE9-3BC17DD667F6"
},
{
"criteria": "cpe:2.3:a:timo_sirainen:dovecot:1.0_beta7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13F7B8F0-CD1A-4851-B24F-F1E8ABCA726B"
}
],
"operator": "OR"
}
]
}
]