5
CVSSv2

CVE-2019-11499

Published: 08/05/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In the IMAP Server in Dovecot 2.3.3 up to and including 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot

fedoraproject fedora 29

fedoraproject fedora 30

opensuse leap 15.0

opensuse leap 15.1

Vendor Advisories

Debian Bug report logs - #928235 dovecot: CVE-2019-11494 CVE-2019-11499 Package: src:dovecot; Maintainer for src:dovecot is Dovecot Maintainers <dovecot@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 30 Apr 2019 14:03:02 UTC Severity: grave Tags: security, upstream Found in ve ...
Dovecot could be made to crash if it received specially crafted network traffic ...
Impact: Moderate Public Date: 2019-04-30 CWE: CWE-617 Bugzilla: 1709240: CVE-2019-11499 dovecot: unacce ...
Submission-login crashes when authentication is started over TLS secured channel and invalid authentication message is sent This can lead to denial-of-service attack by persistent attacker(s) ...