CVE-2013-6171

Source
https://cve.org/CVERecord?id=CVE-2013-6171
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2013-6171.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2013-6171
Downstream
Published
2013-12-09T16:36:47Z
Modified
2026-04-10T03:43:05.360210Z
Summary
[none]
Details

checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.

References

Affected packages