{
  "threat_severity" : "Low",
  "public_date" : "2010-10-01T00:00:00Z",
  "bugzilla" : {
    "description" : "Dovecot: Failed to properly update ACL cache, when multiple rules defined rights for one subject",
    "id" : "640410",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=640410"
  },
  "cvss" : {
    "cvss_base_score" : "5.5",
    "cvss_scoring_vector" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
    "status" : "verified"
  },
  "details" : [ "plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox." ],
  "statement" : "This issue did not affect the version of dovecot package, as shipped with Red\nHat Enterprise Linux 4 and 5. This issue affects the version of dovecot\npackage as shipped with Red Hat Enterprise Linux 6. The Red Hat Security\nResponse Team has rated this issue as having low security impact, a future\nupdate may address this flaw.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2011-05-19T00:00:00Z",
    "advisory" : "RHSA-2011:0600",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "dovecot-1:2.0.9-2.el6"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 4",
    "fix_state" : "Not affected",
    "package_name" : "dovecot",
    "cpe" : "cpe:/o:redhat:enterprise_linux:4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Not affected",
    "package_name" : "dovecot",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2010-3707\nhttps://nvd.nist.gov/vuln/detail/CVE-2010-3707" ],
  "name" : "CVE-2010-3707",
  "csaw" : false
}