PT-2020-19876 · Dovecot+1 · Dovecot+1
Published
2020-02-12
·
Updated
2025-01-30
·
CVE-2020-7957
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Dovecot versions 2.3.9 through 2.3.9.2
Description
The issue arises from the mishandling of snippet generation by the IMAP and LMTP components when a large number of characters must be read to compute the snippet and a trailing > character exists. This results in a denial of service, preventing the recipient from reading all of their messages.
Recommendations
For Dovecot versions 2.3.9 through 2.3.9.2, update to version 2.3.9.3 or later to resolve the issue.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Dovecot