PT-2006-3375 · Dovecot · Dovecot

Bill Boebel

+1

·

Published

2006-05-16

·

Updated

2018-10-18

·

CVE-2006-2414

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dovecot versions 1.0 beta through 1.0
Description A directory traversal issue allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the LIST or DELETE IMAP command.
Recommendations For Dovecot versions 1.0 beta through 1.0, consider restricting access to the LIST and DELETE IMAP commands until a patch is available. As a temporary workaround, restrict the use of ".." sequences in these commands to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2414
DSA-1080-1

Affected Products

Dovecot