CVE-2011-2166Dovecot vulnerability

CWE-168 documents6 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 50.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 24
Latest updateMay 17

Description

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/dovecot< dovecot 1:2.0.13-1 (bookworm)
Debiandovecot/dovecot< 1:2.0.13-1+3
NVDdovecot/dovecot13 versions+12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v9cm-xcfc-8942: script-login in Dovecot 22022-05-17
OSV
CVE-2011-2166: script-login in Dovecot 22011-05-24

📋Vendor Advisories

2
Red Hat
dovecot: authenticated remote bypass of intended access restrictions2011-05-11
Debian
CVE-2011-2166: dovecot - script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group c...2011

💬Community

3
Bugzilla
CVE-2011-2166 dovecot: authenticated remote bypass of intended access restrictions2011-05-30
Bugzilla
CVE-2011-1929 CVE-2011-2166 CVE-2011-2167 dovecot various flaws [fedora-all]2011-05-30
Bugzilla
CVE-2011-2167 dovecot: directory traversal due to not obeying chroot directive2011-05-30