PT-2013-5957 · Dovecot+1 · Dovecot+1

Published

2013-11-28

·

Updated

2018-03-16

·

CVE-2013-6171

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dovecot versions prior to 2.2.7
Description The issue allows local users to bypass authentication and access virtual email accounts. This is achieved by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server. The checkpassword-reply in Dovecot performs setuid operations to a user who is authenticating.
Recommendations For versions prior to 2.2.7, update to version 2.2.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the checkpassword-reply functionality until a patch is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1205
CVE-2013-6171
USN-3556-2

Affected Products

Alt Linux
Dovecot