CVE-2019-10691: High severity dovecot vulnerability
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10691?
CVE-2019-10691 is a vulnerability in Dovecot, a popular email server software, which allows attackers to crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
What is the severity of CVE-2019-10691?
CVE-2019-10691 has a severity rating of high, with a CVSS score of 7.5.
How does CVE-2019-10691 affect Dovecot?
CVE-2019-10691 affects versions of Dovecot before 2.3.5.2, potentially allowing attackers to crash the authentication service.
How can I fix CVE-2019-10691?
To fix CVE-2019-10691, upgrade to Dovecot version 2.3.5.2 or later.
Where can I find more information about CVE-2019-10691?
You can find more information about CVE-2019-10691 on the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00000.html](http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00000.html), [http://www.openwall.com/lists/oss-security/2019/04/18/3](http://www.openwall.com/lists/oss-security/2019/04/18/3), [https://dovecot.org/list/dovecot-news/2019-April/000406.html](https://dovecot.org/list/dovecot-news/2019-April/000406.html)