Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfr9-jq6w-r8wj

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

EPSS

Процентиль: 94%
0.13443
Средний

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 17 лет назад

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

redhat
около 17 лет назад

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

nvd
около 17 лет назад

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

debian
около 17 лет назад

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the ...

EPSS

Процентиль: 94%
0.13443
Средний

Дефекты

CWE-20