Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability

The Dovecot ManageSieve service is prone to a directory-traversal vulnerability because the application fails to adequately sanitize user-supplied input. An attacker may exploit this issue to read or write to arbitrary '.sieve' files.

A successful attack may allow an attacker to obtain potentially sensitive information, cause denial-of-service conditions, or execute arbitrary script code in the context of another user; this may aid in further attacks.

Versions *prior to* the following are affected:

Dovecot 1.2 ManageSieve 0.11.1
Dovecot 1.1 ManageSieve 0.10.4
Dovecot 1.0.15 ManageSieve 9.4







 

Privacy Statement
Copyright 2009, SecurityFocus