CVE-2007-2231

Publication date 25 April 2007

Last updated 24 July 2024


Ubuntu priority

Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.

Status

Package Ubuntu Release Status
dovecot 7.04 feisty
Fixed 1.0.rc17-1ubuntu2.1
6.10 edgy
Fixed 1.0.rc2-1ubuntu2.2
6.06 LTS dapper
Fixed 1.0.beta3-3ubuntu5.5

References

Related Ubuntu Security Notices (USN)

    • USN-487-1
    • Dovecot vulnerability
    • 17 July 2007

Other references