PT-2006-3375 · Dovecot · Dovecot

Bill Boebel

+1

·

Publicado

2006-05-16

·

Atualizado

2018-10-18

·

CVE-2006-2414

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dovecot versions 1.0 beta through 1.0
Description A directory traversal issue allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the LIST or DELETE IMAP command.
Recommendations For Dovecot versions 1.0 beta through 1.0, consider restricting access to the LIST and DELETE IMAP commands until a patch is available. As a temporary workaround, restrict the use of ".." sequences in these commands to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2414
DSA-1080-1

Produtos afetados

Dovecot