CVE-2020-10958: Use After Free
In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10958?
CVE-2020-10958 is a vulnerability in Dovecot before version 2.3.10.1 that allows an unauthenticated attacker to trigger a use-after-free bug, leading to a crash.
What is the severity of CVE-2020-10958?
The severity of CVE-2020-10958 is medium, with a CVSS score of 5.3.
How can CVE-2020-10958 be exploited?
CVE-2020-10958 can be exploited by sending a crafted SMTP/LMTP message to the vulnerable Dovecot server.
How can I check if my version of Dovecot is affected?
You can check if your version of Dovecot is affected by CVE-2020-10958 by comparing the version number with the affected versions (before 2.3.10.1).
How do I fix CVE-2020-10958?
To fix CVE-2020-10958, you should update Dovecot to version 2.3.10.1 or later.