First published: Mon May 18 2020(Updated: )
In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dovecot Dovecot | <2.3.10.1 | |
debian/dovecot | 1:2.3.13+dfsg1-2+deb11u1 1:2.3.13+dfsg1-2+deb11u2 1:2.3.19.1+dfsg1-2.1+deb12u1 1:2.3.21.1+dfsg1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10958 is a vulnerability in Dovecot before version 2.3.10.1 that allows an unauthenticated attacker to trigger a use-after-free bug, leading to a crash.
The severity of CVE-2020-10958 is medium, with a CVSS score of 5.3.
CVE-2020-10958 can be exploited by sending a crafted SMTP/LMTP message to the vulnerable Dovecot server.
You can check if your version of Dovecot is affected by CVE-2020-10958 by comparing the version number with the affected versions (before 2.3.10.1).
To fix CVE-2020-10958, you should update Dovecot to version 2.3.10.1 or later.