https://seclists.org/oss-sec/2024/q3/203: Dovecot CVE-2024-23185: Very large headers can cause source exhaustion when parsing message
Published Aug 15, 2024
·Updated
Affected Software
1 affected component
Dovecot IMAP Server>=2.2<=2.3
Frequently Asked Questions
1
What is the severity of CVE-2024-23185?
CVE-2024-23185 has a confirmed vulnerability type of CWE-770 related to resource management and is considered critical due to the potential for source exhaustion.
2
How do I fix CVE-2024-23185?
To fix CVE-2024-23185, update Dovecot IMAP Server to version 2.3.21.1 or later.
3
Which versions of Dovecot are affected by CVE-2024-23185?
CVE-2024-23185 affects Dovecot versions 2.2 and 2.3.
4
What type of vulnerability is CVE-2024-23185?
CVE-2024-23185 falls under the vulnerability type of allocation of resources without limits or throttling.
5
What component of Dovecot is vulnerable in CVE-2024-23185?
The vulnerable component affected in CVE-2024-23185 is lib-mail.