UBUNTU-CVE-2013-6171
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-6171
UBUNTU-CVE-2013-6171
Summary:
Details: checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.
References: https://ubuntu.com/security/CVE-2013-6171, http://www.dovecot.org/list/dovecot-news/2013-November/000264.html, http://wiki2.dovecot.org/AuthDatabase/CheckPassword#Security, https://ubuntu.com/security/notices/USN-3556-2, https://www.cve.org/CVERecord?id=CVE-2013-6171
Affected packages
Package
Name: dovecot
Purl: pkg:deb/ubuntu/dovecot@1:2.2.9-1ubuntu2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
