Vulnerability Database

289,784

Total vulnerabilities in the database

CVE-2007-2231

Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.

  • Published: Apr 25, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-2231
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:P/I:N/A:N

No CWE or OWASP classifications available.

Software From Fixed in
dovecot / dovecot 1.0.rc20 1.0.rc20.x
dovecot / dovecot 1.0.beta2 1.0.beta2.x
dovecot / dovecot 1.0.beta5 1.0.beta5.x
dovecot / dovecot 1.0.rc15 1.0.rc15.x
dovecot / dovecot 1.0.rc19 1.0.rc19.x
dovecot / dovecot 1.0.rc12 1.0.rc12.x
dovecot / dovecot 1.0.beta4 1.0.beta4.x
dovecot / dovecot 1.0.rc14 1.0.rc14.x
dovecot / dovecot 1.0.beta6 1.0.beta6.x
dovecot / dovecot 1.0.beta9 1.0.beta9.x
dovecot / dovecot 1.0.rc8 1.0.rc8.x
dovecot / dovecot 1.0.rc2 1.0.rc2.x
dovecot / dovecot 1.0.rc25 1.0.rc25.x
dovecot / dovecot 1.0.beta8 1.0.beta8.x
dovecot / dovecot 1.0.beta3 1.0.beta3.x
dovecot / dovecot 1.0.rc16 1.0.rc16.x
dovecot / dovecot 1.0.rc9 1.0.rc9.x
dovecot / dovecot 1.0.rc27 1.0.rc27.x
dovecot / dovecot 1.0.beta1 1.0.beta1.x
dovecot / dovecot 1.0.rc13 1.0.rc13.x
dovecot / dovecot 1.0.rc11 1.0.rc11.x
dovecot / dovecot 1.0.rc6 1.0.rc6.x
dovecot / dovecot 1.0.rc26 1.0.rc26.x
dovecot / dovecot 1.0.rc17 1.0.rc17.x
dovecot / dovecot 1.0.rc3 1.0.rc3.x
dovecot / dovecot 1.0.rc1 1.0.rc1.x
dovecot / dovecot 1.0.rc21 1.0.rc21.x
dovecot / dovecot 1.0.rc22 1.0.rc22.x
dovecot / dovecot 1.0.rc10 1.0.rc10.x
dovecot / dovecot 1.0.rc28 1.0.rc28.x
dovecot / dovecot 1.0.rc7 1.0.rc7.x
dovecot / dovecot 1.0.rc5 1.0.rc5.x
dovecot / dovecot 1.0.rc18 1.0.rc18.x
dovecot / dovecot 1.0.rc23 1.0.rc23.x
dovecot / dovecot 1.0.beta7 1.0.beta7.x
dovecot / dovecot 1.0.rc4 1.0.rc4.x
dovecot / dovecot 1.0.rc24 1.0.rc24.x