PT-2020-12448 · Dovecot+6 · Dovecot+6

Philippe Antoine

·

Published

2020-05-18

·

Updated

2025-01-30

·

CVE-2020-10957

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Dovecot versions prior to 2.3.10.1
Description The issue arises from sending malformed parameters to a NOOP command, which causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp. This can be triggered without authentication.
Recommendations For versions prior to 2.3.10.1, update to version 2.3.10.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the NOOP command to prevent unauthenticated sending of malformed parameters.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1984
ALT-PU-2020-1989
CESA-2020_2901
CVE-2020-10957
DSA-4690-1
MGASA-2020-0222
OPENSUSE-SU-2020:0720-1
OPENSUSE-SU-2020_0720-1
OPENSUSE-SU-2024:10726-1
OPENSUSE-SU-2025:14715-1
RHSA-2020:2901
RHSA-2020_2901
SUSE-SU-2020:1379-1
SUSE-SU-2020:1380-1
SUSE-SU-2020_1379-1
SUSE-SU-2020_1380-1
USN-4361-1

Affected Products

Alt Linux
Centos
Dovecot
Linuxmint
Red Hat
Suse
Ubuntu