vulnerability
FreeBSD: VID-bd98066d-4ea4-11eb-b412-e86a64caca56 (CVE-2020-24386): mail/dovecot -- multiple vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:M/Au:S/C:P/I:P/A:N) | Jan 4, 2021 | Jan 7, 2021 | Dec 10, 2025 |
Severity
5
CVSS
(AV:N/AC:M/Au:S/C:P/I:P/A:N)
Published
Jan 4, 2021
Added
Jan 7, 2021
Modified
Dec 10, 2025
Description
Aki Tuomi reports: When imap hibernation is active, an attacker can cause Dovecot to discover file system directory structure and access other users' emails using specially crafted command. The attacker must have valid credentials to access the mail server. Mail delivery / parsing crashed when the 10 000th MIME part was message/rfc822 (or if parent was multipart/digest). This happened due to earlier MIME parsing changes for CVE-2020-12100.
Solution
freebsd-upgrade-package-dovecot
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.