4.3

CVE-2007-2231

Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.

Data is provided by the National Vulnerability Database (NVD)
DovecotDovecot Version1.0.beta1
DovecotDovecot Version1.0.beta2
DovecotDovecot Version1.0.beta3
DovecotDovecot Version1.0.beta4
DovecotDovecot Version1.0.beta5
DovecotDovecot Version1.0.beta6
DovecotDovecot Version1.0.beta7
DovecotDovecot Version1.0.beta8
DovecotDovecot Version1.0.beta9
DovecotDovecot Version1.0.rc1
DovecotDovecot Version1.0.rc2
DovecotDovecot Version1.0.rc3
DovecotDovecot Version1.0.rc4
DovecotDovecot Version1.0.rc5
DovecotDovecot Version1.0.rc6
DovecotDovecot Version1.0.rc7
DovecotDovecot Version1.0.rc8
DovecotDovecot Version1.0.rc9
DovecotDovecot Version1.0.rc10
DovecotDovecot Version1.0.rc11
DovecotDovecot Version1.0.rc12
DovecotDovecot Version1.0.rc13
DovecotDovecot Version1.0.rc14
DovecotDovecot Version1.0.rc15
DovecotDovecot Version1.0.rc16
DovecotDovecot Version1.0.rc17
DovecotDovecot Version1.0.rc18
DovecotDovecot Version1.0.rc19
DovecotDovecot Version1.0.rc20
DovecotDovecot Version1.0.rc21
DovecotDovecot Version1.0.rc22
DovecotDovecot Version1.0.rc23
DovecotDovecot Version1.0.rc24
DovecotDovecot Version1.0.rc25
DovecotDovecot Version1.0.rc26
DovecotDovecot Version1.0.rc27
DovecotDovecot Version1.0.rc28
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.09% 0.77
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N