CVE-2019-11500: Critical severity dovecot vulnerability
IMAP and ManageSieve protocol parsers do not properly handle NUL byte when scanning data in quoted strings, leading to out of bounds heap memory writes.
Other sources
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-11500?
CVE-2019-11500 is a vulnerability in Dovecot and Pigeonhole that can lead to out-of-bounds writes and remote code execution.
What is the severity of CVE-2019-11500?
CVE-2019-11500 has a severity rating of 9.8 (Critical).
How does CVE-2019-11500 affect Dovecot and Pigeonhole?
CVE-2019-11500 affects Dovecot versions before 2.2.36.4 and 2.3.x before 2.3.7.2, and Pigeonhole versions before 0.5.7.2.
How can CVE-2019-11500 be fixed?
To fix CVE-2019-11500, it is recommended to update Dovecot to version 2.2.36.4 or 2.3.x version 2.3.7.2, and Pigeonhole to version 0.5.7.2.
Is there any additional information available about CVE-2019-11500?
Yes, you can find more information about CVE-2019-11500 at the following references: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00024.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00026.html), [Reference 3](http://www.openwall.com/lists/oss-security/2019/08/28/3)