Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10958

Опубликовано: 18 мая 2020
Источник: nvd
CVSS3: 5.3
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
Версия до 2.3.10.1 (исключая)

EPSS

Процентиль: 77%
0.01029
Низкий

5.3 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

CVSS3: 5.9
redhat
больше 5 лет назад

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

CVSS3: 5.3
debian
больше 5 лет назад

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an un ...

github
больше 3 лет назад

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

oracle-oval
около 5 лет назад

ELSA-2020-4763: dovecot security update (MODERATE)

EPSS

Процентиль: 77%
0.01029
Низкий

5.3 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-416