5
CVSSv2

CVE-2020-25275

Published: 04/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Dovecot prior to 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot

debian debian linux 10.0

fedoraproject fedora 32

Vendor Advisories

Debian Bug report logs - #979363 dovecot: CVE-2020-24386 CVE-2020-25275 Package: src:dovecot; Maintainer for src:dovecot is Dovecot Maintainers <dovecot@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 5 Jan 2021 20:03:04 UTC Severity: grave Tags: security, upstream Found in ve ...
Several vulnerabilities have been discovered in the Dovecot email server CVE-2020-24386 When imap hibernation is active, an attacker (with valid credentials to access the mail server) can cause Dovecot to discover file system directory structures and access other users' emails via specially crafted commands CVE-2020-25275 Inn ...
A security issue was discovered in dovecot version 2311 up to 23113 Mail delivery/parsing crashed when the 10 000th MIME part was message/rfc822 (or if its parent was multipart/digest) This happened due to earlier MIME parsing changes for CVE-2020-12100 Malicious senders could crash dovecot repeatedly by sending/uploading messages with more ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2020-25275: Dovecot: MIME parsing crash <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Aki Tuomi &lt;akituo ...