Back

MEDIUM

dovecot: passdb checkpassword authentication local bypass

Published Dec 9, 2013

Description

checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of dovecot as shipped with Red Hat Enterprise Linux 5, 6 and 7.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 9, 2013
Updated Aug 6, 2024
Reserved Oct 18, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 3, 2013