CVE-2013-6171: Medium severity Dovecot dovecot vulnerability
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/dovecotto a version that resolves this vulnerability.Fixed in 1:2.3.13+dfsg1-2+deb11u1Fixed in 1:2.3.13+dfsg1-2+deb11u4Fixed in 1:2.3.19.1+dfsg1-2.1+deb12u6Fixed in 1:2.4.1+dfsg1-6+deb13u6Fixed in 1:2.4.4+dfsg1-1 - Upgrade
Upgrade
Dovecot checkpassword-replyto a version that resolves this vulnerability.Fixed in 2.2.7
Event History
Frequently Asked Questions
What is CVE-2013-6171?
CVE-2013-6171 is a vulnerability in Dovecot that allows local users to bypass authentication and access virtual email accounts.
What is the severity of CVE-2013-6171?
The severity of CVE-2013-6171 is medium with a CVSS score of 5.8.
How does CVE-2013-6171 work?
CVE-2013-6171 works by performing setuid operations to a user who is authenticating, allowing local users to modify account information and bypass authentication.
What software versions are affected by CVE-2013-6171?
Dovecot versions up to and including 2.2.6 are affected by CVE-2013-6171.
How can I fix CVE-2013-6171?
To fix CVE-2013-6171, you should update Dovecot to version 2.2.7 or higher.