CVE-2021-33515: Command Injection
Published Jun 28, 2021
·Updated
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
Affected Software
4 affected components
Dovecot dovecot<2.3.14.1
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Debian Debian Linux=10.0
Event History
Jun 28, 2021
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
Description
Frequently Asked Questions
1
What is CVE-2021-33515?
CVE-2021-33515 is a vulnerability that allows STARTTLS command injection in the submission service in Dovecot.
2
What is the severity of CVE-2021-33515?
The severity of CVE-2021-33515 is medium.
3
How does CVE-2021-33515 affect Dovecot?
CVE-2021-33515 affects Dovecot versions up to 2.3.14.1.
4
How does CVE-2021-33515 affect Fedora?
CVE-2021-33515 affects Fedora versions 33 and 34.
5
How does CVE-2021-33515 affect Debian Debian Linux?
CVE-2021-33515 affects Debian Debian Linux version 10.0.
6
How can I fix CVE-2021-33515 in Dovecot?
To fix CVE-2021-33515 in Dovecot, you should upgrade to version 2.3.15 or later.