In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dovecot | May 29, 2019 | May 8, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 8, 2019 |
| Debian | — | Upgrade dovecot | Jul 30, 2024 | May 8, 2019 |
| Freebsd | — | Upgrade dovecot | May 1, 2019 | Apr 30, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade dovecot-pigeonholeUpgrade dovecotUpgrade dovecot-mysql | Feb 26, 2020 | May 8, 2019 |
| Suse | — | Upgrade dovecot23-develUpgrade dovecot23-backend-mysqlUpgrade dovecot23-backend-sqliteUpgrade dovecot23-ftsUpgrade dovecot23-fts-solrUpgrade dovecot23-fts-luceneUpgrade dovecot23-backend-pgsqlUpgrade dovecot23Upgrade dovecot23-fts-squat | Oct 8, 2019 | Mar 11, 2019 |
| Ubuntu | — | Upgrade dovecot-coreUpgrade dovecot-submissiond | May 4, 2019 | Mar 11, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub