CVE-2020-25275: Input Validation
Published Jan 4, 2021
·Updated
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
Affected Software
4 affected componentsFixes available
debian/dovecot
1:2.3.4.1-5+deb10u61:2.3.4.1-5+deb10u71:2.3.13+dfsg1-2+deb11u11:2.3.19.1+dfsg1-2.11:2.3.20+dfsg1-11:2.3.21+dfsg1-1
Dovecot dovecot<2.3.13
Debian Debian Linux=10.0
Fedoraproject Fedora=32
Event History
Jan 4, 2021
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25275?
CVE-2020-25275 is a vulnerability in Dovecot before version 2.3.13 that allows an application crash via a crafted email message.
2
How does CVE-2020-25275 affect Dovecot?
CVE-2020-25275 affects Dovecot versions before 2.3.13.
3
What is the severity of CVE-2020-25275?
The severity of CVE-2020-25275 is high, with a CVSS score of 7.5.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-25275?
The CWE ID for CVE-2020-25275 is 20.
5
How can I fix CVE-2020-25275 in Dovecot?
To fix CVE-2020-25275, upgrade Dovecot to version 2.3.13 or later.