5
CVSSv2

CVE-2019-10691

Published: 24/04/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The JSON encoder in Dovecot prior to 2.3.5.2 allows malicious users to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot

opensuse leap 15.0

Vendor Advisories

Dovecot could be made to crash if it received specially crafted network traffic ...
JSON encoder in Dovecot 23 incorrecty assert-crashes when encountering invalid UTF-8 characters This can be used to crash dovecot in two ways Attacker can repeatedly crash Dovecot authentication process by logging in using invalid UTF-8 sequence in username This requires that auth policy is enabled Crash can also occur if OX push notification ...