vulnerability

FreeBSD: VID-a64aa22f-61ec-11e9-85b9-a4badb296695 (CVE-2019-10691): dovecot -- json encoder crash

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Apr 18, 2019
Added
Apr 19, 2019
Modified
Dec 10, 2025

Description

Aki Tuomi reports: * CVE-2019-10691: Trying to login with 8bit username containing invalid UTF8 input causes auth process to crash if auth policy is enabled. This could be used rather easily to cause a DoS. Similar crash also happens during mail delivery when using invalid UTF8 in From or Subject header when OX push notification driver is used.

Solutions

freebsd-upgrade-package-dovecotfreebsd-upgrade-package-dovecot2
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.