Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-59032

Опубликовано: 27 мар. 2026
Источник: redhat
CVSS3: 7.5

Описание

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

A flaw was found in ManageSieve. A remote attacker can exploit this vulnerability by sending a crafted SASL (Simple Authentication and Security Layer) initial response during the AUTHENTICATE command. This can cause the ManageSieve service to crash repeatedly, leading to a Denial of Service (DoS) for other users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dovecotWill not fix
Red Hat Enterprise Linux 10dovecotFixedRHSA-2026:1349804.05.2026
Red Hat Enterprise Linux 10dovecotFixedRHSA-2026:1914919.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportdovecotFixedRHSA-2026:1760214.05.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportdovecotFixedRHSA-2026:2656417.06.2026
Red Hat Enterprise Linux 8dovecotFixedRHSA-2026:1383005.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportdovecotFixedRHSA-2026:1945520.05.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OndovecotFixedRHSA-2026:1945520.05.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportdovecotFixedRHSA-2026:1945320.05.2026
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicedovecotFixedRHSA-2026:1945320.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-229
https://bugzilla.redhat.com/show_bug.cgi?id=2452172dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
nvd
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
debian
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL in ...

CVSS3: 7.5
github
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

rocky
2 месяца назад

Important: dovecot security update

7.5 High

CVSS3