CVE-2023-26434: Medium severity open-xchange app suite backend vulnerability
When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted POP3 server response to reasonable length/size. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26434?
CVE-2023-26434 is a vulnerability that allows an attacker with access to a rogue POP3 service to trigger requests that lead to excessive resource usage and service unavailability.
What is the severity of CVE-2023-26434?
The severity of CVE-2023-26434 is medium with a CVSS score of 4.3.
Which software is affected by CVE-2023-26434?
Open-xchange Open-xchange Appsuite Backend versions up to and including 7.10.6 and 7.10.6-revision_39 are affected by CVE-2023-26434.
How can an attacker exploit CVE-2023-26434?
An attacker with access to a rogue POP3 service can exploit CVE-2023-26434 by triggering requests that cause excessive resource usage and service unavailability.
Is there a fix for CVE-2023-26434?
Yes, updating to a version of Open-xchange Open-xchange Appsuite Backend that is higher than 7.10.6-revision_39 will fix CVE-2023-26434.