CVE-2013-6171
published 2013-12-09CVE-2013-6171: checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and…
PriorityP427medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.46%
70.8th percentile
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.2.9-1 (bookworm) | dovecot 1:2.2.9-1 (bookworm) |
| dovecot | dovecot | <= 2.2.6 | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f2q7-xh76-m34j: checkpassword-reply in Dovecot before 2
ghsa_unreviewed·2022-05-14
CVE-2013-6171 [MEDIUM] CWE-287 GHSA-f2q7-xh76-m34j: checkpassword-reply in Dovecot before 2
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.
OSV
CVE-2013-6171: checkpassword-reply in Dovecot before 2
osv·2013-12-09·CVSS 5.8
CVE-2013-6171 [MEDIUM] CVE-2013-6171: checkpassword-reply in Dovecot before 2
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2018-02-01·CVSS 5.8
CVE-2013-6171 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
USN-3556-1 fixed vulnerabilities in Dovecot. This update
provides the corresponding update for Ubuntu 12.04 ESM.
It was discovered that Dovecot incorrectly handled certain authentications.
An attacker could possibly use this to bypass authentication and access
sensitive information. (CVE-2013-6171)
Original advisory details:
It was discovered that Dovecot incorrectly handled certain authentications.
An attacker could possibly use this to cause a denial of service. (CVE-2017-15132)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dovecot: passdb checkpassword authentication local bypass
vendor_redhat·2013-11-03·CVSS 5.8
CVE-2013-6171 [MEDIUM] dovecot: passdb checkpassword authentication local bypass
dovecot: passdb checkpassword authentication local bypass
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.
Statement: Not vulnerable. This issue did not affect the versions of dovecot as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: dovecot (Red Hat Enterprise Linux 6) - Not affected
Package: dovecot (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-6171: dovecot - checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user...
vendor_debian·2013·CVSS 5.8
CVE-2013-6171 [MEDIUM] CVE-2013-6171: dovecot - checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user...
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.
Scope: local
bookworm: resolved (fixed in 1:2.2.9-1)
bullseye: resolved (fixed in 1:2.2.9-1)
forky: resolved (fixed in 1:2.2.9-1)
sid: resolved (fixed in 1:2.2.9-1)
trixie: resolved (fixed in 1:2.2.9-1)
No detection rules found.
No public exploits indexed.
http://cpanel.net/tsr-2013-0010-full-disclosure/http://secunia.com/advisories/54808http://wiki2.dovecot.org/AuthDatabase/CheckPassword#Securityhttp://www.dovecot.org/list/dovecot-news/2013-November/000264.htmlhttps://usn.ubuntu.com/3556-2/http://cpanel.net/tsr-2013-0010-full-disclosure/http://secunia.com/advisories/54808http://wiki2.dovecot.org/AuthDatabase/CheckPassword#Securityhttp://www.dovecot.org/list/dovecot-news/2013-November/000264.htmlhttps://usn.ubuntu.com/3556-2/
2013-12-09
Published