|
Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
The Dovecot ManageSieve service is prone to a directory-traversal vulnerability because the application fails to adequately sanitize user-supplied input. An attacker may exploit this issue to read or write to arbitrary '.sieve' files. A successful attack may allow an attacker to obtain potentially sensitive information, cause denial-of-service conditions, or execute arbitrary script code in the context of another user; this may aid in further attacks. Versions *prior to* the following are affected: Dovecot 1.2 ManageSieve 0.11.1 Dovecot 1.1 ManageSieve 0.10.4 Dovecot 1.0.15 ManageSieve 9.4 |
|
|
Privacy Statement |