Back

MEDIUM

When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes

Published Jun 20, 2023

Description

When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted SMTP server response to reasonable length/size. No publicly available exploits are known.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OX
Published Jun 20, 2023
Updated Dec 3, 2024
Reserved Feb 22, 2023
CISA Vulnrichment
Updated Jan 19, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a