Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11500

Опубликовано: 28 авг. 2019
Источник: redhat
CVSS3: 8.1

Описание

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

A flaw was found in dovecot. IMAP and ManageSieve protocol parsers do not properly handle the NULL byte when scanning data in quoted strings which leads to an out of bounds heap memory write. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dovecotOut of support scope
Red Hat Enterprise Linux 6dovecotFixedRHSA-2019:288523.09.2019
Red Hat Enterprise Linux 7dovecotFixedRHSA-2019:283620.09.2019
Red Hat Enterprise Linux 8dovecotFixedRHSA-2019:282220.09.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1741141dovecot: improper NULL byte handling in IMAP and ManageSieve protocol parsers leads to out of bounds writes

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

CVSS3: 9.8
nvd
больше 6 лет назад

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

CVSS3: 9.8
debian
больше 6 лет назад

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole be ...

suse-cvrf
больше 6 лет назад

Security update for dovecot22

CVSS3: 9.8
github
больше 3 лет назад

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

8.1 High

CVSS3