Bugzilla – Bug 849671
VUL-0: CVE-2013-6171: dovecot*: passdb checkpassword bypass
Last modified: 2015-06-15 16:26:01 UTC
CVE-2013-6171 http://wiki2.dovecot.org/AuthDatabase/CheckPassword#Security * Some usage of passdb checkpassword could have been exploitable by local users. You may need to modify your setup to keep it working. See http://wiki2.dovecot.org/AuthDatabase/CheckPassword#Security References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6171 https://bugzilla.redhat.com/show_bug.cgi?id=1028589 http://wiki2.dovecot.org/AuthDatabase/CheckPassword#Security http://www.dovecot.org/list/dovecot-news/2013-November/000264.html http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=729063
bugbot adjusting priority
I'm not sure why this bug is assigned to maintenance@opensuse.org. Alexandre, if you have a fix, please open a maintenancerequest with your fixed package. (keep in mind to add the bugids, cveids and added/changed patches to your changelog-entry) Thanks! Reassigned to Alexandre.