Loading...
Loading...
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.
December 9, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-6171
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.