PT-2020-19876 · Dovecot+1 · Dovecot+1

Published

2020-02-12

·

Updated

2025-01-30

·

CVE-2020-7957

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Dovecot versions 2.3.9 through 2.3.9.2
Description The issue arises from the mishandling of snippet generation by the IMAP and LMTP components when a large number of characters must be read to compute the snippet and a trailing > character exists. This results in a denial of service, preventing the recipient from reading all of their messages.
Recommendations For Dovecot versions 2.3.9 through 2.3.9.2, update to version 2.3.9.3 or later to resolve the issue.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1984
CVE-2020-7957
OPENSUSE-SU-2024:10726-1
OPENSUSE-SU-2025:14715-1

Affected Products

Alt Linux
Dovecot