Lucene search

K
nvd[email protected]NVD:CVE-2013-6171
HistoryDec 09, 2013 - 4:36 p.m.

CVE-2013-6171

2013-12-0916:36:47
CWE-287
web.nvd.nist.gov
1

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

56.4%

checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.

Affected configurations

NVD
Node
dovecotdovecotRange2.2.6
OR
dovecotdovecotMatch2.0beta1
OR
dovecotdovecotMatch2.0.0
OR
dovecotdovecotMatch2.0.1
OR
dovecotdovecotMatch2.0.2
OR
dovecotdovecotMatch2.0.3
OR
dovecotdovecotMatch2.0.4
OR
dovecotdovecotMatch2.0.5
OR
dovecotdovecotMatch2.0.6
OR
dovecotdovecotMatch2.0.7
OR
dovecotdovecotMatch2.0.8
OR
dovecotdovecotMatch2.0.9
OR
dovecotdovecotMatch2.0.10
OR
dovecotdovecotMatch2.0.11
OR
dovecotdovecotMatch2.0.12
OR
dovecotdovecotMatch2.0.13
OR
dovecotdovecotMatch2.0.14
OR
dovecotdovecotMatch2.0.15
OR
dovecotdovecotMatch2.1rc1
OR
dovecotdovecotMatch2.1rc2
OR
dovecotdovecotMatch2.1rc3
OR
dovecotdovecotMatch2.1rc5
OR
dovecotdovecotMatch2.1rc6
OR
dovecotdovecotMatch2.1rc7
OR
dovecotdovecotMatch2.1.0
OR
dovecotdovecotMatch2.1.1
OR
dovecotdovecotMatch2.1.2
OR
dovecotdovecotMatch2.1.3
OR
dovecotdovecotMatch2.1.4
OR
dovecotdovecotMatch2.1.5
OR
dovecotdovecotMatch2.1.6
OR
dovecotdovecotMatch2.1.7
OR
dovecotdovecotMatch2.1.10
OR
dovecotdovecotMatch2.1.11
OR
dovecotdovecotMatch2.1.12
OR
dovecotdovecotMatch2.1.13
OR
dovecotdovecotMatch2.1.14
OR
dovecotdovecotMatch2.1.15
OR
dovecotdovecotMatch2.2rc1
OR
dovecotdovecotMatch2.2rc2
OR
dovecotdovecotMatch2.2rc3
OR
dovecotdovecotMatch2.2rc4
OR
dovecotdovecotMatch2.2rc5
OR
dovecotdovecotMatch2.2rc6
OR
dovecotdovecotMatch2.2rc7
OR
dovecotdovecotMatch2.2.0
OR
dovecotdovecotMatch2.2.1
OR
dovecotdovecotMatch2.2.2
OR
dovecotdovecotMatch2.2.3
OR
dovecotdovecotMatch2.2.4
OR
dovecotdovecotMatch2.2.5

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

56.4%