https://seclists.org/oss-sec/2024/q3/202: Dovecot CVE-2024-23184: Having a large number of addss headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive
Published Aug 15, 2024
·Updated
Affected Software
1 affected component
Dovecot IMAP Server>=2.2<=2.3
Frequently Asked Questions
1
What is the severity of CVE-2024-23184?
CVE-2024-23184 has been classified as a moderate severity vulnerability due to its potential to exhaust CPU resources.
2
How do I fix CVE-2024-23184?
To fix CVE-2024-23184, upgrade your Dovecot IMAP Server to version 2.3.21.1 or later.
3
What versions of Dovecot are vulnerable to CVE-2024-23184?
Dovecot versions 2.2 and 2.3 are vulnerable to CVE-2024-23184.
4
What is the vulnerability type for CVE-2024-23184?
CVE-2024-23184 falls under the vulnerability type CWE-770, which involves allocation of resources without limits or throttling.
5
Is there a workaround for CVE-2024-23184?
No specific workaround is recommended for CVE-2024-23184; upgrading to the fixed version is advised.