Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-33515

Опубликовано: 21 июн. 2021
Источник: redhat
CVSS3: 4.2

Описание

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

It was found that dovecot could still accept plaintext commands while the STARTTLS negotiation process is ongoing. This could allow an active person in the middle, with valid credentials on dovecot, to, for example, steal confidential data such as the client's emails and passwords.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotNot affected
Red Hat Enterprise Linux 9dovecotAffected
Red Hat Enterprise Linux 8dovecotFixedRHSA-2022:195010.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1973610dovecot: plaintext commands injection

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVSS3: 4.8
nvd
около 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVSS3: 4.8
debian
около 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS comman ...

rocky
около 3 лет назад

Moderate: dovecot security update

CVSS3: 4.8
github
около 3 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

4.2 Medium

CVSS3