CVE-2020-12100: High severity Dovecot dovecot vulnerability
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12100?
CVE-2020-12100 is a vulnerability in Dovecot that allows remote attackers to cause a denial of service by sending a crafted e-mail message with deeply nested MIME parts.
What is the severity of CVE-2020-12100?
The severity of CVE-2020-12100 is high with a severity value of 7.5.
How does CVE-2020-12100 affect Dovecot?
CVE-2020-12100 affects versions of Dovecot before 2.3.11.3.
How can I fix CVE-2020-12100?
To fix CVE-2020-12100, update Dovecot to version 2.3.11.3 or later.
Where can I find more information about CVE-2020-12100?
You can find more information about CVE-2020-12100 on the following websites: [http://seclists.org/fulldisclosure/2021/Jan/18](http://seclists.org/fulldisclosure/2021/Jan/18), [http://www.openwall.com/lists/oss-security/2020/08/12/1](http://www.openwall.com/lists/oss-security/2020/08/12/1), [http://www.openwall.com/lists/oss-security/2021/01/04/3](http://www.openwall.com/lists/oss-security/2021/01/04/3).