[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-6171Date: (C)2013-12-09   (M)2023-12-22


checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.8
Exploit Score: 8.6
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-54808
USN-3556-2
http://www.dovecot.org/list/dovecot-news/2013-November/000264.html
http://cpanel.net/tsr-2013-0010-full-disclosure/
http://wiki2.dovecot.org/AuthDatabase/CheckPassword#Security

CPE    51
cpe:/a:dovecot:dovecot:2.2:rc1
cpe:/a:dovecot:dovecot:2.2:rc2
cpe:/a:dovecot:dovecot:2.1.0
cpe:/a:dovecot:dovecot:2.1.1
...
CWE    1
CWE-287

© SecPod Technologies