Back

MEDIUM

Dovecot: Failed to update ACL cache for mailboxes stored in private namespace

Published Oct 6, 2010

Description

plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of dovecot as shipped with Red Hat Enterprise Linux 4, 5 or 6.

Metrics

Weaknesses (1)

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 6, 2010
Updated Aug 7, 2024
Reserved Oct 1, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Oct 1, 2010