CVE-2010-3707
Last modified
CVE-2010-3707 is a vulnerability of currently unknown severity. plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.. EPSS estimates a 2.67% chance of exploitation in the next 30 days.
Description
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dovecot | Dovecot | 1.2.0 |
| Dovecot | Dovecot | 1.2.1 |
| Dovecot | Dovecot | 1.2.2 |
| Dovecot | Dovecot | 1.2.3 |
| Dovecot | Dovecot | 1.2.4 |
| Dovecot | Dovecot | 1.2.5 |
| Dovecot | Dovecot | 1.2.6 |
| Dovecot | Dovecot | 1.2.7 |
| Dovecot | Dovecot | 1.2.8 |
| Dovecot | Dovecot | 1.2.9 |
| Dovecot | Dovecot | 1.2.10 |
| Dovecot | Dovecot | 1.2.11 |
| Dovecot | Dovecot | 1.2.12 |
| Dovecot | Dovecot | 1.2.13 |
| Dovecot | Dovecot | 1.2.14 |
| Dovecot | Dovecot | 2.0.0 |
| Dovecot | Dovecot | 2.0.1 |
| Dovecot | Dovecot | 2.0.2 |
| Dovecot | Dovecot | 2.0.3 |
| Dovecot | Dovecot | 2.0.4 |
References
- http://www.dovecot.org/list/dovecot/2010-October/053450.htmlVendor Advisory
- http://www.dovecot.org/list/dovecot/2010-October/053451.htmlVendor Advisory
- http://www.dovecot.org/list/dovecot/2010-October/053452.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2010/2572Vendor Advisory
- http://www.dovecot.org/list/dovecot/2010-October/053450.htmlVendor Advisory
- http://www.dovecot.org/list/dovecot/2010-October/053451.htmlVendor Advisory
- http://www.dovecot.org/list/dovecot/2010-October/053452.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2010/2572Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3707?
How severe is CVE-2010-3707?
How do I fix CVE-2010-3707?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3701lib/MessageStoreImpl.cpp in Red Hat Enterprise MRG before 1.…
- CVE-2010-3702The Gfx::getPos function in the PDF parser in xpdf before 3.…
- CVE-2010-3703The PostScriptFunction::PostScriptFunction function in poppl…
- CVE-2010-3704The FoFiType1::parse function in fofi/FoFiType1.cc in the PD…
- CVE-2010-3705The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in t…
- CVE-2010-3706plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.…
- CVE-2010-3708The serialization implementation in JBoss Drools in Red Hat …
- CVE-2010-3709The ZipArchive::getArchiveComment function in PHP 5.2.x thro…
- CVE-2010-3710Stack consumption vulnerability in the filter_var function i…
- CVE-2010-3711libpurple in Pidgin before 2.7.4 does not properly validate …
- CVE-2010-3712Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x be…
- CVE-2010-3713rss.php in UseBB before 1.0.11 does not properly handle foru…
Are you affected by CVE-2010-3707?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
