First published: Wed Feb 12 2020(Updated: )
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dovecot Dovecot | >=2.3.9<2.3.9.3 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-7046.
The title of this vulnerability is 'lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 dat…'.
CVE-2020-7046 has a severity level of high.
Dovecot version 2.3.9 before 2.3.9.3 and Fedora versions 30 and 31 are affected by CVE-2020-7046.
To fix the vulnerability CVE-2020-7046, you should update Dovecot to version 2.3.9.3 or later.