Submitted by KeesCook on Tue, 2007-07-17 21:56
Referenced CVEs:
CVE-2007-2231
Description:
===========================================================
Ubuntu Security Notice USN-487-1 July 17, 2007
dovecot vulnerability
CVE-2007-2231
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
dovecot-common 1.0.beta3-3ubuntu5.5
Ubuntu 6.10:
dovecot-common 1.0.rc2-1ubuntu2.2
Ubuntu 7.04:
dovecot-common 1.0.rc17-1ubuntu2.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that Dovecot, when configured to use non-system-user
spools and compressed folders, would allow directory traversals in
mailbox names. Remote authenticated users could potentially read email
owned by other users.


