Description
In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4690-1 | dovecot security update |
EUVD |
EUVD-2020-3362 | In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command. |
Ubuntu USN |
USN-4361-1 | Dovecot vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:21:13.881Z
Reserved: 2020-03-25T00:00:00.000Z
Link: CVE-2020-10958
No data.
Status : Modified
Published: 2020-05-18T14:15:11.827
Modified: 2024-11-21T04:56:27.237
Link: CVE-2020-10958
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN