Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10958

Опубликовано: 18 мая 2020
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dovecotNot affected
Red Hat Enterprise Linux 6dovecotNot affected
Red Hat Enterprise Linux 7dovecotNot affected
Red Hat Enterprise Linux 8dovecotFixedRHSA-2020:476304.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1834323dovecot: command followed by sufficient number of newlines leads to use-after-free

EPSS

Процентиль: 82%
0.01657
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

CVSS3: 5.3
nvd
больше 5 лет назад

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

CVSS3: 5.3
debian
больше 5 лет назад

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an un ...

github
больше 3 лет назад

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

oracle-oval
около 5 лет назад

ELSA-2020-4763: dovecot security update (MODERATE)

EPSS

Процентиль: 82%
0.01657
Низкий

5.9 Medium

CVSS3