PT-2011-3655 · Dovecot+2 · Dovecot+2

Henri Salo

·

Publicado

2011-05-24

·

Atualizado

2017-08-29

·

CVE-2011-2167

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dovecot versions 2.0.x through 2.0.12
Description The issue concerns a problem where the script-login in Dovecot does not follow the chroot configuration setting. This might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
Recommendations For Dovecot versions 2.0.x through 2.0.12, update to version 2.0.13 or later to resolve the issue.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2013_0520
CVE-2011-2167
RHSA-2013:0520
RHSA-2013_0520

Produtos afetados

Centos
Dovecot
Red Hat