Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-33515

Опубликовано: 28 июн. 2021
Источник: debian
EPSS Низкий

Описание

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dovecotfixed1:2.3.13+dfsg1-2package
dovecotnot-affectedstretchpackage

Примечания

  • https://dovecot.org/pipermail/dovecot-news/2021-June/000462.html

  • https://www.openwall.com/lists/oss-security/2021/06/28/2

EPSS

Процентиль: 88%
0.03726
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVSS3: 4.2
redhat
около 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVSS3: 4.8
nvd
около 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

rocky
около 3 лет назад

Moderate: dovecot security update

CVSS3: 4.8
github
около 3 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

EPSS

Процентиль: 88%
0.03726
Низкий