First published: Wed Apr 24 2019(Updated: )
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dovecot | <2.3.5.2 | |
SUSE Linux | =15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10691 is a vulnerability in Dovecot, a popular email server software, which allows attackers to crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
CVE-2019-10691 has a severity rating of high, with a CVSS score of 7.5.
CVE-2019-10691 affects versions of Dovecot before 2.3.5.2, potentially allowing attackers to crash the authentication service.
To fix CVE-2019-10691, upgrade to Dovecot version 2.3.5.2 or later.
You can find more information about CVE-2019-10691 on the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00000.html](http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00000.html), [http://www.openwall.com/lists/oss-security/2019/04/18/3](http://www.openwall.com/lists/oss-security/2019/04/18/3), [https://dovecot.org/list/dovecot-news/2019-April/000406.html](https://dovecot.org/list/dovecot-news/2019-April/000406.html)