CVE-2020-28200: Medium severity dovecot vulnerability
Published Jun 28, 2021
·Updated
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
Affected Software
3 affected components
Dovecot dovecot<2.3.15
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Event History
Jun 28, 2021
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-28200.
2
What is the severity of CVE-2020-28200?
The severity of CVE-2020-28200 is medium with a CVSS score of 4.3.
3
What is affected by CVE-2020-28200?
Dovecot versions before 2.3.15 and Fedora versions 33 and 34 are affected by CVE-2020-28200.
4
What is the impact of CVE-2020-28200?
CVE-2020-28200 allows uncontrolled resource consumption, leading to a potential denial of service.
5
How can I fix CVE-2020-28200?
Update Dovecot to version 2.3.15 or higher and update Fedora to the latest available patches.