Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Innokentii Sennovskiy

#37180of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2020-5857
7.5
2020-09-11
Dovecot · Dovecot · CVE-2020-25275
Name of the Vulnerable Software and Affected Versions: Dovecot versions prior to 2.3.13 Description: The issue is related to insufficient input validation in the lda, lmtp, and imap components of the Dovecot mail server. This allows a remote attacker to cause a denial of service by crafting a specific email message with certain choices for ten thousand MIME parts, leading to an application crash. Recommendations: For versions prior to 2.3.13, update to version 2.3.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of the lda, lmtp, and imap components until a patch is applied. Avoid processing crafted email messages with excessive MIME parts in the affected components.