CVE-2007-2231

UnknownEPSS 2.12%

Last modified

CVE-2007-2231 is a vulnerability of currently unknown severity. Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.. EPSS estimates a 2.12% chance of exploitation in the next 30 days.

Description

Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.

Metrics

EPSS Probability
2.12%

79.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
DovecotDovecot1.0.beta1
DovecotDovecot1.0.beta2
DovecotDovecot1.0.beta3
DovecotDovecot1.0.beta4
DovecotDovecot1.0.beta5
DovecotDovecot1.0.beta6
DovecotDovecot1.0.beta7
DovecotDovecot1.0.beta8
DovecotDovecot1.0.beta9
DovecotDovecot1.0.rc1
DovecotDovecot1.0.rc2
DovecotDovecot1.0.rc3
DovecotDovecot1.0.rc4
DovecotDovecot1.0.rc5
DovecotDovecot1.0.rc6
DovecotDovecot1.0.rc7
DovecotDovecot1.0.rc8
DovecotDovecot1.0.rc9
DovecotDovecot1.0.rc10
DovecotDovecot1.0.rc11
DovecotDovecot1.0.rc12
DovecotDovecot1.0.rc13
DovecotDovecot1.0.rc14
DovecotDovecot1.0.rc15
DovecotDovecot1.0.rc16
DovecotDovecot1.0.rc17
DovecotDovecot1.0.rc18
DovecotDovecot1.0.rc19
DovecotDovecot1.0.rc20
DovecotDovecot1.0.rc21
DovecotDovecot1.0.rc22
DovecotDovecot1.0.rc23
DovecotDovecot1.0.rc24
DovecotDovecot1.0.rc25
DovecotDovecot1.0.rc26
DovecotDovecot1.0.rc27
DovecotDovecot1.0.rc28

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-2231?
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
How severe is CVE-2007-2231?
Severity scoring for CVE-2007-2231 is pending analysis. The EPSS model estimates a 2.12% probability of exploitation in the next 30 days.
How do I fix CVE-2007-2231?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-2231?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST