CVE-2024-25584: Medium severity dovecot vulnerability
Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails. Upgrade to latest released version. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25584?
CVE-2024-25584 has a moderate severity level due to its potential to split emails during relaying.
How do I fix CVE-2024-25584?
To fix CVE-2024-25584, upgrade to the latest version of Dovecot.
What impact does CVE-2024-25584 have on email functionality?
CVE-2024-25584 can cause a single email containing LF DOT LF to be split into two separate emails.
What does CVE-2024-25584 affect specifically?
CVE-2024-25584 affects Dovecot's handling of email data commands according to RFC standards.
Is CVE-2024-25584 a configuration issue?
No, CVE-2024-25584 is not a configuration issue but rather a flaw in how Dovecot processes email commands.