Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10957

Опубликовано: 18 мая 2020
Источник: redhat
CVSS3: 7.5

Описание

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

A flaw was found in Dovecot, where it did not properly handle certain malformed NOOP commands. This flaw allows a malicious attacker to cause the submission, submission-login, or lmtp services to crash by sending specially crafted commands.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dovecotNot affected
Red Hat Enterprise Linux 6dovecotNot affected
Red Hat Enterprise Linux 7dovecotNot affected
Red Hat Enterprise Linux 8dovecotFixedRHSA-2020:290113.07.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1834317dovecot: malformed NOOP commands leads to DoS

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

CVSS3: 7.5
nvd
больше 5 лет назад

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

CVSS3: 7.5
debian
больше 5 лет назад

In Dovecot before 2.3.10.1, unauthenticated sending of malformed param ...

github
больше 3 лет назад

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

oracle-oval
больше 5 лет назад

ELSA-2020-2901: dovecot security update (IMPORTANT)

7.5 High

CVSS3