PT-2019-3525 · Dovecot+3 · Dovecot+3
CVE-2019-11494
·
Publicado
2019-04-30
·
Atualizado
2025-01-30
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Dovecot versions 2.3.3 through 2.3.5.2
Description
The issue is related to the implementation of the Internet Message Access Protocol (IMAP) in the Dovecot mail server, specifically a null pointer dereference. This can be exploited by a remote attacker to cause a denial of service. The submission-login service crashes when the client disconnects prematurely during the AUTH command.
Recommendations
For Dovecot versions 2.3.3 through 2.3.5.2, consider disabling the submission-login service as a temporary workaround until a patch is available. Restrict access to the IMAP server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Dovecot
Suse
Ubuntu