Unrated severityNVD Advisory· Published Dec 9, 2013· Updated Apr 29, 2026
CVE-2013-6171
CVE-2013-6171
Description
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.
Affected products
51cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*+ 50 more
- cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*range: <=2.2.6
- cpe:2.3:a:dovecot:dovecot:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.11:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.12:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.13:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.14:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.15:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1:rc1:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1:rc2:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1:rc3:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1:rc5:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1:rc6:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.1:rc7:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2:rc1:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2:rc2:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2:rc3:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2:rc4:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2:rc5:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2:rc6:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.2:rc7:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.