[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251782

 
 

909

 
 

196543

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2020-1435 --- dovecot

ID: oval:org.secpod.oval:def:1601205Date: (C)2020-11-05   (M)2023-11-10
Class: PATCHFamily: unix




A flaw was found in dovecot. A remote attacker could cause a denial of service by repeatedly sending emails containing MIME parts containing malicious content of which dovecot will attempt to parse. The highest threat from this vulnerability is to system availability. In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service via a crafted e-mail message with deeply nested MIME parts. In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read. A flaw was found in dovecot. An out-of-bounds read flaw was found in the way dovecot handled NTLM authentication allowing an attacker to crash the dovecot auth process repeatedly preventing login. The highest threat from this vulnerability is to system availability. In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled. A flaw was found in dovecot. An attacker can use the way dovecot handles RPA to crash the authentication process repeatedly preventing login. The highest threat from this vulnerability is to system availability

Platform:
Amazon Linux AMI
Product:
dovecot
Reference:
ALAS-2020-1435
CVE-2020-12100
CVE-2020-12673
CVE-2020-12674
CVE    3
CVE-2020-12673
CVE-2020-12674
CVE-2020-12100

© SecPod Technologies