Red Hat Bugzilla – Bug 640401
CVE-2010-3706 Dovecot: Failed to update ACL cache for mailboxes stored in private namespace
Last modified: 2015-07-31 02:32:31 EDT
A security flaw was found in the way Dovecot IMAP server updated own Access Control List (ACL) cache for rules specifying user rights on mailboxes stored in the private namespace of the particular user. A local attacker could use this flaw to prevent the mailbox administrator to restrict the ACL rule via a symlink attack on the shared mailbox. References: [1] http://www.dovecot.org/list/dovecot/2010-October/053450.html [2] http://www.dovecot.org/list/dovecot/2010-October/053452.html [3] http://wiki.dovecot.org/ACL
Statement: Not vulnerable. This issue did not affect the versions of dovecot as shipped with Red Hat Enterprise Linux 4, 5 or 6.