5.8
CVSSv2

CVE-2013-6171

Published: 09/12/2013 Updated: 16/03/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

checkpassword-reply in Dovecot prior to 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot 2.0.12

dovecot dovecot 2.0.13

dovecot dovecot 2.0.6

dovecot dovecot 2.0.7

dovecot dovecot 2.1

dovecot dovecot 2.1.0

dovecot dovecot 2.1.15

dovecot dovecot 2.1.2

dovecot dovecot 2.2.5

dovecot dovecot 2.2.4

dovecot dovecot 2.2

dovecot dovecot 2.0

dovecot dovecot 2.0.14

dovecot dovecot 2.0.15

dovecot dovecot 2.0.8

dovecot dovecot 2.0.9

dovecot dovecot 2.1.1

dovecot dovecot 2.1.10

dovecot dovecot 2.1.3

dovecot dovecot 2.1.4

dovecot dovecot 2.2.3

dovecot dovecot 2.2.2

dovecot dovecot 2.0.0

dovecot dovecot 2.0.1

dovecot dovecot 2.0.2

dovecot dovecot 2.0.3

dovecot dovecot 2.1.11

dovecot dovecot 2.1.12

dovecot dovecot 2.1.5

dovecot dovecot 2.1.6

dovecot dovecot 2.2.1

dovecot dovecot 2.2.0

dovecot dovecot 2.0.10

dovecot dovecot 2.0.11

dovecot dovecot 2.0.4

dovecot dovecot 2.0.5

dovecot dovecot 2.1.13

dovecot dovecot 2.1.14

dovecot dovecot 2.1.7

dovecot dovecot

Vendor Advisories

Debian Bug report logs - #729063 dovecot: CVE-2013-6171 Package: dovecot; Maintainer for dovecot is Dovecot Maintainers <dovecot@packagesdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 8 Nov 2013 13:33:02 UTC Severity: important Tags: confirmed, security, wheezy Found in version 1:225-1 ...
Several security issues were fixed in Dovecot ...