CVE-2020-24386: Medium severity dovecot vulnerability
Published Jan 4, 2021
·Updated
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
Affected Software
4 affected componentsFixes available
debian/dovecot
1:2.3.4.1-5+deb10u61:2.3.4.1-5+deb10u71:2.3.13+dfsg1-2+deb11u11:2.3.19.1+dfsg1-2.11:2.3.20+dfsg1-11:2.3.21+dfsg1-1
Dovecot dovecot>=2.2.26<2.3.13
Debian Debian Linux=10.0
Fedoraproject Fedora=32
Event History
Jan 4, 2021
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
Description
Frequently Asked Questions
1
What is CVE-2020-24386?
CVE-2020-24386 is a vulnerability in Dovecot, versions before 2.3.13, that allows an authenticated attacker to access other users' email messages and disclose the server's file path.
2
How can an attacker exploit CVE-2020-24386?
An attacker can exploit CVE-2020-24386 by using IMAP IDLE to trigger unhibernation with attacker-controlled parameters.
3
What is the severity of CVE-2020-24386?
CVE-2020-24386 has a severity rating of 6.8 (Medium).
4
Which versions of Dovecot are affected by CVE-2020-24386?
Versions of Dovecot before 2.3.13 are affected by CVE-2020-24386.
5
How can I fix CVE-2020-24386?
To fix CVE-2020-24386, you need to update Dovecot to version 2.3.13 or later.