9.8
CVE-2019-11500
- EPSS 41.27%
- Veröffentlicht 29.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:12
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dovecot ≫ Pigeonhole Version < 0.5.7.2
Debian ≫ Debian Linux Version8.0
Fedoraproject ≫ Fedora Version30
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 41.27% | 0.972 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.