Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x_server | 10.6.1 | 10.6.1.x |
| apple / mac_os_x_server | 10.6.2 | 10.6.2.x |
| apple / mac_os_x | 10.6.1 | 10.6.1.x |
| apple / mac_os_x_server | 10.6.0 | 10.6.0.x |
| apple / mac_os_x | 10.6.0 | 10.6.0.x |
| apple / mac_os_x | 10.6.2 | 10.6.2.x |