Dovecot

Dovecot

53 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.03%
  • Veröffentlicht 18.05.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:56:27

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

Exploit
  • EPSS 10.65%
  • Veröffentlicht 18.05.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:56:27

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 12.02.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:05

The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read a...

  • EPSS 0.43%
  • Veröffentlicht 12.02.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:33

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

  • EPSS 1.21%
  • Veröffentlicht 13.12.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:35:15

In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 05.11.2019 22:15:10
  • Zuletzt bearbeitet 21.11.2024 02:53:21

A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.

Exploit
  • EPSS 41.27%
  • Veröffentlicht 29.08.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:21:12

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

  • EPSS 0.86%
  • Veröffentlicht 08.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:21:11

In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.

  • EPSS 0.75%
  • Veröffentlicht 08.05.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:21:12

In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.

  • EPSS 0.81%
  • Veröffentlicht 24.04.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:19:45

The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.