Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-24386

Опубликовано: 04 янв. 2021
Источник: debian

Описание

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dovecotfixed1:2.3.13+dfsg1-1package

Примечания

  • https://dovecot.org/pipermail/dovecot-news/2021-January/000450.html

  • https://github.com/dovecot/core/commit/00df2308b0733e810824545183d73276c416cdd3

  • https://github.com/dovecot/core/commit/b4a9872b833b7985c7d0e7615f1b7fc812dd4c55

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVSS3: 6.8
redhat
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVSS3: 6.8
nvd
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

suse-cvrf
около 5 лет назад

Security update for dovecot22

CVSS3: 6.8
github
больше 3 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).