lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade dovecot | Dec 1, 2016 | May 24, 2011 |
| Debian | — | Upgrade dovecot | Jul 30, 2024 | May 24, 2011 |
| Freebsd | — | Upgrade dovecot | Dec 10, 2025 | Aug 19, 2011 |
| Gentoo Linux | — | Upgrade net-mail/dovecot. | Oct 30, 2017 | May 24, 2011 |
| Oracle_linux | — | Upgrade dovecotUpgrade dovecot-pgsqlUpgrade dovecot-develUpgrade dovecot-pigeonholeUpgrade dovecot-mysql | Oct 16, 2024 | May 24, 2011 |
| Suse | — | Upgrade dovecot12-backend-sqliteUpgrade dovecot20-backend-pgsqlUpgrade dovecot20-fts-solrUpgrade dovecot20Upgrade dovecot12Upgrade dovecot20-backend-sqliteUpgrade dovecot12-backend-mysqlUpgrade dovecot12-fts-solrUpgrade dovecot12-fts-luceneUpgrade dovecot12-develUpgrade dovecot20-develUpgrade dovecot12-backend-pgsqlUpgrade dovecot20-backend-mysql | Feb 17, 2015 | May 24, 2011 |
| Ubuntu | — | Upgrade dovecot-common | Nov 8, 2024 | May 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub