CVE-2020-7957: Input Validation
The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7957?
CVE-2020-7957 is a vulnerability in the IMAP and LMTP components in Dovecot versions 2.3.9 before 2.3.9.3 that allows a denial of service attack.
What is the severity of CVE-2020-7957?
The severity of CVE-2020-7957 is medium, with a severity value of 5.3.
How does CVE-2020-7957 affect Dovecot?
CVE-2020-7957 affects Dovecot versions 2.3.9 before 2.3.9.3, causing a denial of service that prevents recipients from reading all of their messages.
Which software versions are affected by CVE-2020-7957?
Dovecot versions 2.3.9 before 2.3.9.3 and Fedoraproject Fedora versions 30 and 31 are affected by CVE-2020-7957.
How can I fix the CVE-2020-7957 vulnerability?
To fix the CVE-2020-7957 vulnerability, update your Dovecot software to version 2.3.9.3 or higher.