Vulnerabilities
Vulnerable Software
Dovecot:  >> Dovecot  >> 1.0_rc29  Security Vulnerabilities
The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
CVSS Score
5.0
EPSS Score
0.008
Published
2008-10-15
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
CVSS Score
4.4
EPSS Score
0.0
Published
2008-03-06


Contact Us

Shodan ® - All rights reserved