Rapid7 Vulnerability & Exploit Database

FreeBSD: VID-37D106A8-15A4-483E-8247-FCB68B16EAF8 (CVE-2020-10957): Dovecot -- Multiple vulnerabilities

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

FreeBSD: VID-37D106A8-15A4-483E-8247-FCB68B16EAF8 (CVE-2020-10957): Dovecot -- Multiple vulnerabilities

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
04/02/2020
Created
05/20/2020
Added
05/19/2020
Modified
10/20/2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.

From VID-37D106A8-15A4-483E-8247-FCB68B16EAF8:

Aki Tuomi reports:

Vulnerability Details:

Sending malformed NOOP command causes crash in submission, submission-login or

lmtp service.

Risk:

Remote attacker can keep submission-login service down, causing denial of

service attack. For lmtp the risk is neglible, as lmtp is usually behind a

trusted MTA.

Steps to reproduce:

Send ``NOOP EE"FY`` to submission port, or similarly malformed command.

Vulnerability Details:

Sending command followed by sufficient number of newlines triggers a

use-after-free bug that might crash submission-login, submission or

lmtp service.

Risk:

Remote attacker can keep submission-login service down, causing denial

of service attack. For lmtp the risk is neglible, as lmtp is usually

behind a trusted MTA.

Steps to reproduce:

This can be currently reproduced with ASAN or Valgrind. Reliable way to

crash has not yet been discovered.

Vulnerability Details:

Sending mail with empty quoted localpart causes submission or lmtp component

to crash.

Risk:

Malicious actor can cause denial of service to mail delivery by repeatedly

sending mails with bad sender or recipient address.

Steps to reproduce:

Send mail with envelope sender or recipient as <""@example.org>.

Workaround:

For submission there is no workaround, but triggering the bug requires valid

credentials.

For lmtp, one can implement sufficient filtering on MTA level to prevent mails

with such addresses from ending up in LMTP delivery.

Solution(s)

  • freebsd-upgrade-package-dovecot

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;