CVE-2020-12674: High severity Dovecot dovecot vulnerability
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12674?
CVE-2020-12674 is a vulnerability in Dovecot versions prior to 2.3.11.3 that allows an attacker to crash the auth service by sending a specially formatted RPA request.
What is the severity of CVE-2020-12674?
CVE-2020-12674 has a severity score of 7.5 (high).
How does CVE-2020-12674 affect Dovecot?
CVE-2020-12674 affects Dovecot versions before 2.3.11.3.
How can I fix CVE-2020-12674?
To fix CVE-2020-12674, you should update Dovecot to version 2.3.11.3 or later.
Where can I find more information about CVE-2020-12674?
You can find more information about CVE-2020-12674 at the following references: http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00048.html, http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00059.html, and https://dovecot.org/security.