9.8
CVE-2019-11500
- EPSS 41.27%
- Veröffentlicht 29.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:12
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dovecot ≫ Pigeonhole Version < 0.5.7.2
Debian ≫ Debian Linux Version8.0
Fedoraproject ≫ Fedora Version30
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 41.27% | 0.973 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.