CVE-2020-7046: High severity Dovecot dovecot vulnerability
Published Feb 12, 2020
·Updated
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
Affected Software
3 affected components
Dovecot dovecot>=2.3.9<2.3.9.3
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Event History
Feb 12, 2020
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-7046.
2
What is the title of this vulnerability?
The title of this vulnerability is 'lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 dat…'.
3
What is the severity level of CVE-2020-7046?
CVE-2020-7046 has a severity level of high.
4
Which software is affected by CVE-2020-7046?
Dovecot version 2.3.9 before 2.3.9.3 and Fedora versions 30 and 31 are affected by CVE-2020-7046.
5
How can I fix the vulnerability CVE-2020-7046?
To fix the vulnerability CVE-2020-7046, you should update Dovecot to version 2.3.9.3 or later.