Unrated severityNVD Advisory· Published May 24, 2011· Updated Apr 29, 2026
CVE-2011-2166
CVE-2011-2166
Description
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
Affected products
13cpe:2.3:a:dovecot:dovecot:2.0.0:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:dovecot:dovecot:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- dovecot.org/pipermail/dovecot/2011-May/059085.htmlnvdPatch
- openwall.com/lists/oss-security/2011/05/18/4nvdPatch
- rhn.redhat.com/errata/RHSA-2013-0520.htmlnvd
- secunia.com/advisories/52311nvd
- www.dovecot.org/doc/NEWS-2.0nvd
- www.securityfocus.com/bid/48003nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/67675nvd
News mentions
0No linked articles in our index yet.