CVE-2013-2111: Input Validation
Published May 27, 2014
·Updated
The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.
Affected Software
9 affected components
Dovecot dovecot<=2.2.1
Dovecot dovecot=2.2-rc1
Dovecot dovecot=2.2-rc2
Dovecot dovecot=2.2-rc3
Dovecot dovecot=2.2-rc4
Dovecot dovecot=2.2-rc5
Dovecot dovecot=2.2-rc6
Dovecot dovecot=2.2-rc7
Dovecot dovecot=2.2.0
Remediation
Event History
May 27, 2014
CVE Published
02:55 PM
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2111?
CVE-2013-2111 has been classified with a severity that indicates it can lead to denial of service due to CPU exhaustion.
2
How do I fix CVE-2013-2111?
To fix CVE-2013-2111, upgrade Dovecot to version 2.2.2 or later.
3
Which versions of Dovecot are affected by CVE-2013-2111?
CVE-2013-2111 affects Dovecot versions up to and including 2.2.1 and all release candidates of version 2.2.
4
What attack vector is associated with CVE-2013-2111?
CVE-2013-2111 is exploited via remote attackers sending invalid APPEND parameters to the IMAP functionality.
5
What are the potential consequences of not addressing CVE-2013-2111?
Failure to address CVE-2013-2111 could result in service disruption and increased CPU consumption on the affected Dovecot servers.