Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4907

Опубликовано: 04 нояб. 2008
Источник: nvd
CVSS2: 4.3
EPSS Средний

Описание

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dovecot:dovecot:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:dovecot:dovecot:1.1.5:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.13443
Средний

4.3 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 17 лет назад

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

redhat
около 17 лет назад

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

debian
около 17 лет назад

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the ...

github
больше 3 лет назад

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

EPSS

Процентиль: 94%
0.13443
Средний

4.3 Medium

CVSS2

Дефекты

CWE-20