CVE-2011-2166: Medium severity dovecot vulnerability
Published May 24, 2011
·Updated
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
Affected Software
13 affected components
Dovecot dovecot=2.0.0
Dovecot dovecot=2.0.1
Dovecot dovecot=2.0.2
Dovecot dovecot=2.0.3
Dovecot dovecot=2.0.4
Dovecot dovecot=2.0.5
Dovecot dovecot=2.0.6
Dovecot dovecot=2.0.7
Dovecot dovecot=2.0.8
Dovecot dovecot=2.0.9
Dovecot dovecot=2.0.10
Dovecot dovecot=2.0.11
Dovecot dovecot=2.0.12
Remediation
Patch Available
Patch Available
Event History
May 24, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2166?
CVE-2011-2166 is considered to be a moderate severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2011-2166?
To fix CVE-2011-2166, you should upgrade Dovecot to version 2.0.13 or later.
3
Who is affected by CVE-2011-2166?
CVE-2011-2166 affects users of Dovecot versions 2.0.0 to 2.0.12.
4
What type of vulnerability is CVE-2011-2166?
CVE-2011-2166 is a user privilege escalation vulnerability that may allow authenticated users to bypass access controls.
5
Is CVE-2011-2166 exploitable remotely?
Yes, CVE-2011-2166 can be exploited by remote authenticated users.