vulnerability
FreeBSD: VID-a64aa22f-61ec-11e9-85b9-a4badb296695 (CVE-2019-10691): dovecot -- json encoder crash
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Apr 18, 2019 | Apr 19, 2019 | Dec 10, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Apr 18, 2019
Added
Apr 19, 2019
Modified
Dec 10, 2025
Description
Aki Tuomi reports: * CVE-2019-10691: Trying to login with 8bit username containing invalid UTF8 input causes auth process to crash if auth policy is enabled. This could be used rather easily to cause a DoS. Similar crash also happens during mail delivery when using invalid UTF8 in From or Subject header when OX push notification driver is used.
Solutions
freebsd-upgrade-package-dovecotfreebsd-upgrade-package-dovecot2
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.