Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2gj-cmfm-c4j4

Опубликовано: 27 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

EPSS

Процентиль: 50%
0.00703
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-229

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
redhat
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
nvd
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
debian
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL in ...

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость почтового сервера Dovecot, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 50%
0.00703
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-229