The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dovecot | Jul 2, 2019 | Apr 24, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 24, 2019 |
| Debian | — | Upgrade dovecot | Jul 30, 2024 | Apr 24, 2019 |
| Freebsd | — | Upgrade dovecot2Upgrade dovecot | Apr 19, 2019 | Apr 18, 2019 |
| Gentoo Linux | — | Upgrade net-mail/dovecot. | Sep 3, 2019 | Apr 24, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade dovecot-mysqlUpgrade dovecotUpgrade dovecot-pigeonhole | Jun 27, 2019 | Apr 24, 2019 |
| Suse | — | Upgrade dovecot23-ftsUpgrade dovecot23-develUpgrade dovecot23-backend-sqliteUpgrade dovecot23-fts-luceneUpgrade dovecot23Upgrade dovecot23-fts-solrUpgrade dovecot23-backend-mysqlUpgrade dovecot23-backend-pgsqlUpgrade dovecot23-fts-squat | May 3, 2019 | Apr 9, 2019 |
| Ubuntu | — | Upgrade dovecot-core | Apr 30, 2019 | Apr 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub