Описание
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
A flaw was found in dovecot. A remote attacker could cause a denial of service by repeatedly sending emails containing MIME parts containing malicious content of which dovecot will attempt to parse. The highest threat from this vulnerability is to system availability.
Меры по смягчению последствий
Upstream suggests that this flaw can be mitigated by limiting MIME structures in MTA
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | dovecot | Not affected | ||
Red Hat Enterprise Linux 6 | dovecot | Affected | ||
Red Hat Enterprise Linux 7 | dovecot | Fixed | RHSA-2020:3617 | 03.09.2020 |
Red Hat Enterprise Linux 8 | dovecot | Fixed | RHSA-2020:3713 | 10.09.2020 |
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | dovecot | Fixed | RHSA-2020:3735 | 14.09.2020 |
Red Hat Enterprise Linux 8.1 Extended Update Support | dovecot | Fixed | RHSA-2020:3736 | 14.09.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp ...
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
Уязвимость почтового сервера Dovecot, вызванная неконтролируемой рекурсией, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3