5.3
CVSSv3

CVE-2020-10958

Published: 18/05/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Dovecot prior to 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot

Vendor Advisories

Synopsis Moderate: dovecot security update Type/Severity Security Advisory: Moderate Topic An update for dovecot is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Debian Bug report logs - #960963 dovecot: CVE-2020-10957 CVE-2020-10958 CVE-2020-10967 Package: src:dovecot; Maintainer for src:dovecot is Dovecot Maintainers <dovecot@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 18 May 2020 19:45:06 UTC Severity: grave Tags: security, upstre ...
Several security issues were fixed in Dovecot ...
Several vulnerabilities were discovered in the Dovecot email server, which could cause crashes in the submission, submission-login or lmtp services, resulting in denial of service For the stable distribution (buster), these problems have been fixed in version 1:2341-5+deb10u2 We recommend that you upgrade your dovecot packages For the detaile ...
A security issue has been found in Dovecot before 23101 in the lmtp/submission component Sending many invalid or unknown commands can cause the server to access freed memory, which can lead to a server crash This happens when the server closes the connection with a "421 Too many invalid commands" error The bad command limit depends on the ser ...

Exploits

Open-Xchange Dovecot versions 230 through 2310 suffer from null pointer dereference and denial of service vulnerabilities ...