First published: Mon May 18 2020(Updated: )
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/dovecot | <=1:2.3.2-1<=1:2.3.7.2-1<=1:2.3.4.1-5+deb10u1 | 1:2.3.4.1-5+deb10u2 1:2.3.10.1+dfsg1-1 |
Dovecot Dovecot | <2.3.10.1 | |
debian/dovecot | 1:2.3.13+dfsg1-2+deb11u1 1:2.3.13+dfsg1-2+deb11u2 1:2.3.19.1+dfsg1-2.1+deb12u1 1:2.3.21.1+dfsg1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10957 is a vulnerability in Dovecot before 2.3.10.1 that allows unauthenticated sending of malformed parameters to a NOOP command, causing a NULL Pointer Dereference and crash.
CVE-2020-10957 can be exploited by an attacker to cause a denial of service (crash) in the submission-login, submission, or lmtp components of Dovecot.
CVE-2020-10957 has a severity rating of 7.5 (high).
To fix CVE-2020-10957, upgrade to Dovecot version 2.3.10.1 or later.
You can find more information about CVE-2020-10957 at the following references: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00059.html), [Link 2](http://packetstormsecurity.com/files/157771/Open-Xchange-Dovecot-2.3.10-Null-Pointer-Dereference-Denial-Of-Service.html), [Link 3](http://seclists.org/fulldisclosure/2020/May/37).