CVE-2021-28374
Linux Debian vulnerability analysis and mitigation

Overview

The Debian courier-authlib package before version 0.71.1-2 for Courier Authentication Library created a /run/courier/authdaemon directory with weak permissions. The vulnerability was discovered in March 2021 and was assigned CVE-2021-28374. The issue affected multiple versions of courier-authlib including 0.71.1-1, 0.71.0-1, 0.69.0-2, and 0.66.4-9 (Debian Bug).

Technical details

The vulnerability stems from incorrect permission assignments for a critical resource, specifically the /run/courier/authdaemon directory. The weak permissions allowed unauthorized access to the authentication daemon's socket directory. The issue has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (NVD).

Impact

The vulnerability allowed attackers to read sensitive user information through the exposed directory. The accessible information included user existence confirmation, UIDs, GIDs, home directory paths, Maildir locations, quota information, and password-related data such as hashes. In some configurations, cleartext passwords could also be exposed (Debian LTS).

Exploitability

The vulnerability could be exploited by any user with access to the system, as the directory permissions were too permissive. The authtest utility could be used to query user database information, potentially enabling brute force attacks when combined with the authpasswd tool (Debian Bug).

Mitigation and workarounds

The issue was fixed in courier-authlib version 0.71.1-2 by tightening permissions on the /run/courier/authdaemon directory. For Debian 9 (stretch), the fix was backported to version 0.66.4-9+deb9u1. A temporary workaround before patching involved manually restricting access to the authtest program by setting permissions to 750 and ownership to courier:root (Debian LTS).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9318MEDIUM4.8
  • Linux Debian logoLinux Debian
  • taglib
NoNoAug 12, 2026
CVE-2026-19566NONEN/A
  • Linux Debian logoLinux Debian
  • libnet-cidr-set-perl
NoNoAug 12, 2026
CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 12, 2026
CVE-2026-68449NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 12, 2026
CVE-2026-68448NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management