First published: Mon May 18 2020(Updated: )
In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dovecot Dovecot | <2.3.10.1 | |
debian/dovecot | 1:2.3.13+dfsg1-2+deb11u1 1:2.3.13+dfsg1-2+deb11u2 1:2.3.19.1+dfsg1-2.1+deb12u1 1:2.3.21.1+dfsg1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10967 is a vulnerability in Dovecot that allows remote unauthenticated attackers to crash the lmtp or submission process by sending mail with an empty localpart.
CVE-2020-10967 has a severity of medium with a CVSS score of 5.3.
CVE-2020-10967 affects Dovecot versions before 2.3.10.1, allowing attackers to crash the lmtp or submission process.
To fix CVE-2020-10967, upgrade to Dovecot version 2.3.10.1 or higher.
You can find more information about CVE-2020-10967 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00059.html, http://packetstormsecurity.com/files/157771/Open-Xchange-Dovecot-2.3.10-Null-Pointer-Dereference-Denial-Of-Service.html, http://seclists.org/fulldisclosure/2020/May/37