// For flags

CVE-2007-2231

Directory traversal in dovecot with zlib plugin

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.

Vulnerabilidad de escalado de directorio en index/mbox/mbox-storage.c de Dovecot versiones anteriores a 1.0.rc29, cuando se usa la extensión (plugin) zlib, permite a atacantes remotos leer buzones de correo (mbox files) comprimidos con gzip (.gz) de su elección mediante una secuencia .. (punto punto) en el nombre del buzón.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-04-25 CVE Reserved
  • 2007-04-25 CVE Published
  • 2024-06-20 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.beta1
Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta1"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.beta2
Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta2"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.beta3
Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta3"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.beta4
Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta4"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.beta5
Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta5"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.beta6
Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta6"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.beta7
Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta7"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.beta8
Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta8"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.beta9
Search vendor "Dovecot" for product "Dovecot" and version "1.0.beta9"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc1
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc1"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc2
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc2"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc3
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc3"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc4
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc4"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc5
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc5"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc6
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc6"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc7
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc7"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc8
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc8"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc9
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc9"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc10
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc10"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc11
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc11"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc12
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc12"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc13
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc13"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc14
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc14"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc15
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc15"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc16
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc16"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc17
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc17"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc18
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc18"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc19
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc19"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc20
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc20"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc21
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc21"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc22
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc22"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc23
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc23"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc24
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc24"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc25
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc25"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc26
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc26"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc27
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc27"
-
Affected
Dovecot
Search vendor "Dovecot"
Dovecot
Search vendor "Dovecot" for product "Dovecot"
1.0.rc28
Search vendor "Dovecot" for product "Dovecot" and version "1.0.rc28"
-
Affected