MEDIUM
dovecot: sending mail with empty quoted localpart leads to DoS
Published May 18, 2020
5.3
MEDIUMCVSS 3.1
EPSS 8.15%
Description
In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
dovecot-1:2.3.8-4.el8
Fixed · RHSA-2020:4763
Red Hat Enterprise Linux 5
dovecot
Not affected
Red Hat Enterprise Linux 6
dovecot
Not affected
Red Hat Enterprise Linux 7
dovecot
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | dovecot-1:2.3.8-4.el8 | Fixed | RHSA-2020:4763 |
| Red Hat Enterprise Linux 5 | dovecot | Not affected | n/a |
| Red Hat Enterprise Linux 6 | dovecot | Not affected | n/a |
| Red Hat Enterprise Linux 7 | dovecot | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00059.html vendor-advisoryx_refsource_SUSE
- http://packetstormsecurity.com/files/157771/Open-Xchange-Dovecot-2.3.10-Null-Pointer-Dereference-Denial-Of-Service.html x_refsource_MISC
- http://seclists.org/fulldisclosure/2020/May/37 mailing-listx_refsource_FULLDISCExploitThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/05/18/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-10967 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1834326 Issue Tracking
- https://dovecot.org/pipermail/dovecot-news/2020-May/000438.html
- https://dovecot.org/security x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-3368 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4AAX2MJEULPVSRZOBX3PNPFSYP4FM4TT/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EYZU6CHA3VMYYAUCMHSCCQKJEVEIKPQ2/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TTZN2VW55ZC2AQBGBJMLRJSZIKSB2NS6/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VVUWHUUAFPC6XGIXYFIPTNBXLHPNM4W6/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XKKAL3OMG76ZZ7CIEMQP2K6KCTD2RAKE/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-10967
- https://usn.ubuntu.com/4361-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2020-10967
- https://www.debian.org/security/2020/dsa-4690 vendor-advisoryx_refsource_DEBIAN
- https://www.openwall.com/lists/oss-security/2020/05/18/1 x_refsource_CONFIRMMailing ListThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 18, 2020
Updated Aug 4, 2024
Reserved Mar 26, 2020
Link CVE-2020-10967
CISA Vulnrichment
No data
GitHub
No data