Описание
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
Релиз | Статус | Примечание |
---|---|---|
bionic | not-affected | code not present |
devel | released | 2.3.13+dfsg1-1ubuntu2 |
esm-infra-legacy/trusty | not-affected | code not present |
esm-infra/bionic | not-affected | code not present |
esm-infra/focal | not-affected | 1:2.3.7.2-1ubuntu3.4 |
esm-infra/xenial | not-affected | code not present |
focal | released | 1:2.3.7.2-1ubuntu3.4 |
groovy | released | 1:2.3.11.3+dfsg1-2ubuntu0.2 |
hirsute | released | 1:2.3.13+dfsg1-1ubuntu1.1 |
impish | released | 2.3.13+dfsg1-1ubuntu2 |
Показывать по
EPSS
5.8 Medium
CVSS2
4.8 Medium
CVSS3
Связанные уязвимости
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
The submission service in Dovecot before 2.3.15 allows STARTTLS comman ...
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
EPSS
5.8 Medium
CVSS2
4.8 Medium
CVSS3