CVE-2020-10957: Null Pointer Dereference
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10957?
CVE-2020-10957 is a vulnerability in Dovecot before 2.3.10.1 that allows unauthenticated sending of malformed parameters to a NOOP command, causing a NULL Pointer Dereference and crash.
How does CVE-2020-10957 impact Dovecot?
CVE-2020-10957 can be exploited by an attacker to cause a denial of service (crash) in the submission-login, submission, or lmtp components of Dovecot.
What is the severity of CVE-2020-10957?
CVE-2020-10957 has a severity rating of 7.5 (high).
How can I fix CVE-2020-10957?
To fix CVE-2020-10957, upgrade to Dovecot version 2.3.10.1 or later.
Where can I find more information about CVE-2020-10957?
You can find more information about CVE-2020-10957 at the following references: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00059.html), [Link 2](http://packetstormsecurity.com/files/157771/Open-Xchange-Dovecot-2.3.10-Null-Pointer-Dereference-Denial-Of-Service.html), [Link 3](http://seclists.org/fulldisclosure/2020/May/37).