First published: Mon Jun 28 2021(Updated: )
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dovecot Dovecot | <2.3.15 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-28200.
The severity of CVE-2020-28200 is medium with a CVSS score of 4.3.
Dovecot versions before 2.3.15 and Fedora versions 33 and 34 are affected by CVE-2020-28200.
CVE-2020-28200 allows uncontrolled resource consumption, leading to a potential denial of service.
Update Dovecot to version 2.3.15 or higher and update Fedora to the latest available patches.