CVE-2011-2166
published 2011-05-24CVE-2011-2166: script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass…
PriorityP428medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.01%
78.8th percentile
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.0.13-1 (bookworm) | dovecot 1:2.0.13-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | >= 0 < 1:2.0.13-1 | 1:2.0.13-1 |
| dovecot | dovecot | >= 0 < 1:2.0.13-1 | 1:2.0.13-1 |
| dovecot | dovecot | >= 0 < 1:2.0.13-1 | 1:2.0.13-1 |
| dovecot | dovecot | >= 0 < 1:2.0.13-1 | 1:2.0.13-1 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v9cm-xcfc-8942: script-login in Dovecot 2
ghsa_unreviewed·2022-05-17
CVE-2011-2166 [MEDIUM] GHSA-v9cm-xcfc-8942: script-login in Dovecot 2
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
OSV
CVE-2011-2166: script-login in Dovecot 2
osv·2011-05-24·CVSS 6.5
CVE-2011-2166 [MEDIUM] CVE-2011-2166: script-login in Dovecot 2
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
Red Hat
dovecot: authenticated remote bypass of intended access restrictions
vendor_redhat·2011-05-11·CVSS 6.5
CVE-2011-2166 [MEDIUM] dovecot: authenticated remote bypass of intended access restrictions
dovecot: authenticated remote bypass of intended access restrictions
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
Package: dovecot (Red Hat Enterprise Linux 4) - Not affected
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2011-2166: dovecot - script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group c...
vendor_debian·2011·CVSS 6.5
CVE-2011-2166 [MEDIUM] CVE-2011-2166: dovecot - script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group c...
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
Scope: local
bookworm: resolved (fixed in 1:2.0.13-1)
bullseye: resolved (fixed in 1:2.0.13-1)
forky: resolved (fixed in 1:2.0.13-1)
sid: resolved (fixed in 1:2.0.13-1)
trixie: resolved (fixed in 1:2.0.13-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2166 dovecot: authenticated remote bypass of intended access restrictions
bugzilla·2011-05-30·CVSS 6.5
CVE-2011-2166 [MEDIUM] CVE-2011-2166 dovecot: authenticated remote bypass of intended access restrictions
CVE-2011-2166 dovecot: authenticated remote bypass of intended access restrictions
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-2166 to
the following vulnerability:
Name: CVE-2011-2166
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2166
Assigned: 20110524
Reference: http://dovecot.org/pipermail/dovecot/2011-May/059085.html
Reference: http://openwall.com/lists/oss-security/2011/05/18/4
Reference: http://www.dovecot.org/doc/NEWS-2.0
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user
and group configuration settings, which might allow remote
authenticated users to bypass intended access restrictions by
leveraging a script.
Discussion:
Created dovecot tracking bugs for this issue
Affects: fedora-all [bug 709108]
---
Upstream patch:
Bugzilla
CVE-2011-1929 CVE-2011-2166 CVE-2011-2167 dovecot various flaws [fedora-all]
bugzilla·2011-05-30·CVSS 5.0
CVE-2011-1929 [MEDIUM] CVE-2011-1929 CVE-2011-2166 CVE-2011-2167 dovecot various flaws [fedora-all]
CVE-2011-1929 CVE-2011-2166 CVE-2011-2167 dovecot various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=706286
Please note: this issue affects multip
Bugzilla
CVE-2011-2167 dovecot: directory traversal due to not obeying chroot directive
bugzilla·2011-05-30·CVSS 6.5
CVE-2011-2167 [MEDIUM] CVE-2011-2167 dovecot: directory traversal due to not obeying chroot directive
CVE-2011-2167 dovecot: directory traversal due to not obeying chroot directive
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-2167 to
the following vulnerability:
Name: CVE-2011-2167
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2167
Assigned: 20110524
Reference: http://dovecot.org/pipermail/dovecot/2011-May/059085.html
Reference: http://openwall.com/lists/oss-security/2011/05/18/4
Reference: http://www.dovecot.org/doc/NEWS-2.0
script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot
configuration setting, which might allow remote authenticated users to
conduct directory traversal attacks by leveraging a script.
Discussion:
Created dovecot tracking bugs for this issue
Affects: fedora-all [bug 709108]
---
Looking at the upstream NEWS
http://dovecot.org/pipermail/dovecot/2011-May/059085.htmlhttp://openwall.com/lists/oss-security/2011/05/18/4http://rhn.redhat.com/errata/RHSA-2013-0520.htmlhttp://secunia.com/advisories/52311http://www.dovecot.org/doc/NEWS-2.0http://www.securityfocus.com/bid/48003https://exchange.xforce.ibmcloud.com/vulnerabilities/67675http://dovecot.org/pipermail/dovecot/2011-May/059085.htmlhttp://openwall.com/lists/oss-security/2011/05/18/4http://rhn.redhat.com/errata/RHSA-2013-0520.htmlhttp://secunia.com/advisories/52311http://www.dovecot.org/doc/NEWS-2.0http://www.securityfocus.com/bid/48003https://exchange.xforce.ibmcloud.com/vulnerabilities/67675
2011-05-24
Published