First published: Wed Feb 12 2020(Updated: )
The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dovecot Dovecot | >=2.3.9<2.3.9.3 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7957 is a vulnerability in the IMAP and LMTP components in Dovecot versions 2.3.9 before 2.3.9.3 that allows a denial of service attack.
The severity of CVE-2020-7957 is medium, with a severity value of 5.3.
CVE-2020-7957 affects Dovecot versions 2.3.9 before 2.3.9.3, causing a denial of service that prevents recipients from reading all of their messages.
Dovecot versions 2.3.9 before 2.3.9.3 and Fedoraproject Fedora versions 30 and 31 are affected by CVE-2020-7957.
To fix the CVE-2020-7957 vulnerability, update your Dovecot software to version 2.3.9.3 or higher.