PT-2019-3525 · Dovecot+3 · Dovecot+3

Published

2019-04-30

·

Updated

2025-01-30

·

CVE-2019-11494

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Dovecot versions 2.3.3 through 2.3.5.2
Description The issue is related to the implementation of the Internet Message Access Protocol (IMAP) in the Dovecot mail server, specifically a null pointer dereference. This can be exploited by a remote attacker to cause a denial of service. The submission-login service crashes when the client disconnects prematurely during the AUTH command.
Recommendations For Dovecot versions 2.3.3 through 2.3.5.2, consider disabling the submission-login service as a temporary workaround until a patch is available. Restrict access to the IMAP server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2531
ALT-PU-2019-2533
BDU:2019-03702
CVE-2019-11494
OPENSUSE-SU-2019:2278-1
OPENSUSE-SU-2019:2281-1
OPENSUSE-SU-2019_2278-1
OPENSUSE-SU-2019_2281-1
OPENSUSE-SU-2024:10726-1
OPENSUSE-SU-2025:14715-1
SUSE-SU-2019:2514-1
SUSE-SU-2019_2514-1
USN-3961-1

Affected Products

Alt Linux
Dovecot
Suse
Ubuntu