In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dovecot | Jan 2, 2020 | Dec 13, 2019 |
| Freebsd | — | Upgrade dovecot | Dec 14, 2019 | Dec 13, 2019 |
| Suse | — | Upgrade dovecot23-backend-mysqlUpgrade dovecot23-fts-solrUpgrade dovecot23-develUpgrade dovecot23-ftsUpgrade dovecot23Upgrade dovecot23-backend-sqliteUpgrade dovecot23-backend-pgsqlUpgrade dovecot23-fts-squatUpgrade dovecot23-fts-lucene | Feb 4, 2022 | Dec 10, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub