PT-2019-3525 · Dovecot+3 · Dovecot+3
Published
2019-04-30
·
Updated
2025-01-30
·
CVE-2019-11494
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Dovecot versions 2.3.3 through 2.3.5.2
Description
The issue is related to the implementation of the Internet Message Access Protocol (IMAP) in the Dovecot mail server, specifically a null pointer dereference. This can be exploited by a remote attacker to cause a denial of service. The submission-login service crashes when the client disconnects prematurely during the AUTH command.
Recommendations
For Dovecot versions 2.3.3 through 2.3.5.2, consider disabling the submission-login service as a temporary workaround until a patch is available. Restrict access to the IMAP server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Dovecot
Suse
Ubuntu