CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dovecot:dovecot:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:2.0.12:*:*:*:*:*:*:*

History

21 Nov 2024, 01:27

Type Values Removed Values Added
References () http://dovecot.org/pipermail/dovecot/2011-May/059085.html - Patch () http://dovecot.org/pipermail/dovecot/2011-May/059085.html - Patch
References () http://openwall.com/lists/oss-security/2011/05/18/4 - Patch () http://openwall.com/lists/oss-security/2011/05/18/4 - Patch
References () http://rhn.redhat.com/errata/RHSA-2013-0520.html - () http://rhn.redhat.com/errata/RHSA-2013-0520.html -
References () http://secunia.com/advisories/52311 - () http://secunia.com/advisories/52311 -
References () http://www.dovecot.org/doc/NEWS-2.0 - () http://www.dovecot.org/doc/NEWS-2.0 -
References () http://www.securityfocus.com/bid/48003 - () http://www.securityfocus.com/bid/48003 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/67674 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/67674 -

Information

Published : 2011-05-24 23:55

Updated : 2024-11-21 01:27


NVD link : CVE-2011-2167

Mitre link : CVE-2011-2167

CVE.ORG link : CVE-2011-2167


JSON object : View

Products Affected

dovecot

  • dovecot
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')