Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10957

Опубликовано: 18 мая 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

A flaw was found in Dovecot, where it did not properly handle certain malformed NOOP commands. This flaw allows a malicious attacker to cause the submission, submission-login, or lmtp services to crash by sending specially crafted commands.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dovecotNot affected
Red Hat Enterprise Linux 6dovecotNot affected
Red Hat Enterprise Linux 7dovecotNot affected
Red Hat Enterprise Linux 8dovecotFixedRHSA-2020:290113.07.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1834317dovecot: malformed NOOP commands leads to DoS

EPSS

Процентиль: 94%
0.07167
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

CVSS3: 7.5
nvd
около 6 лет назад

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

CVSS3: 7.5
debian
около 6 лет назад

In Dovecot before 2.3.10.1, unauthenticated sending of malformed param ...

github
около 4 лет назад

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

oracle-oval
около 6 лет назад

ELSA-2020-2901: dovecot security update (IMPORTANT)

EPSS

Процентиль: 94%
0.07167
Низкий

7.5 High

CVSS3