5

CVE-2006-2414

Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Timo SirainenDovecot Version1.0
Timo SirainenDovecot Version1.0_beta2
Timo SirainenDovecot Version1.0_beta3
Timo SirainenDovecot Version1.0_beta7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.39% 0.818
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://dovecot.org/list/dovecot-cvs/2006-May/005563.html
http://secunia.com/advisories/20308
http://secunia.com/advisories/20315
http://securityreason.com/securityalert/913
http://www.debian.org/security/2006/dsa-1080
http://www.dovecot.org/list/dovecot-news/2006-May/000006.html
Patch
http://www.securityfocus.com/archive/1/433878/100/0/threaded
http://www.securityfocus.com/bid/17961
Patch
http://www.vupen.com/english/advisories/2006/2013
https://exchange.xforce.ibmcloud.com/vulnerabilities/26536