Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10691

Опубликовано: 18 апр. 2019
Источник: redhat
CVSS3: 7.5

Описание

The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.

Отчет

A flaw was found in the JSON encoder in dovecot, which an attacker could use to crash the application via usage of invalid UTF-8 characters in the login name during authentication or by using invalid UTF-8 sequence in email when OX push notification driver is enabled. The versions of dovecot shipped with Red Hat Enterprise Linux did not ship the vulnerable code and therefore were not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dovecotNot affected
Red Hat Enterprise Linux 6dovecotNot affected
Red Hat Enterprise Linux 7dovecotNot affected
Red Hat Enterprise Linux 8dovecotNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-228
https://bugzilla.redhat.com/show_bug.cgi?id=1701216dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack.

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.

CVSS3: 7.5
nvd
почти 7 лет назад

The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.

CVSS3: 7.5
debian
почти 7 лет назад

The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeate ...

suse-cvrf
почти 7 лет назад

Security update for dovecot23

suse-cvrf
почти 7 лет назад

Security update for dovecot23

7.5 High

CVSS3