The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-dovecot | Jul 2, 2019 | Apr 24, 2019 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Apr 24, 2019 | |
| Debian | debian-upgrade-dovecot | Jul 30, 2024 | Apr 24, 2019 | |
| Freebsd | freebsd-upgrade-package-dovecotfreebsd-upgrade-package-dovecot2 | Apr 19, 2019 | Apr 18, 2019 | |
| Gentoo Linux | gentoo-linux-upgrade-net-mail-dovecot | Sep 3, 2019 | Apr 24, 2019 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-dovecothuawei-euleros-2_0_sp8-upgrade-dovecot-mysqlhuawei-euleros-2_0_sp8-upgrade-dovecot-pigeonhole | Jun 27, 2019 | Apr 24, 2019 | |
| Suse | — | suse-upgrade-dovecot23suse-upgrade-dovecot23-backend-mysqlsuse-upgrade-dovecot23-backend-pgsqlsuse-upgrade-dovecot23-backend-sqlitesuse-upgrade-dovecot23-develsuse-upgrade-dovecot23-ftssuse-upgrade-dovecot23-fts-lucenesuse-upgrade-dovecot23-fts-solrsuse-upgrade-dovecot23-fts-squat | May 3, 2019 | Apr 9, 2019 |
| Ubuntu | ubuntu-upgrade-dovecot-core | Apr 30, 2019 | Apr 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub