Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-59032

Опубликовано: 27 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

РелизСтатусПримечание
devel

not-affected

1:2.4.2+dfsg1-3ubuntu2
esm-infra-legacy/trusty

needed

esm-infra-legacy/xenial

needed

esm-infra/bionic

needed

esm-infra/focal

needed

esm-infra/xenial

ignored

end of ESM support, was needed
jammy

released

1:2.3.16+dfsg1-3ubuntu2.7
noble

released

1:2.3.21+dfsg1-2ubuntu6.3
questing

released

1:2.4.1+dfsg1-5ubuntu4.1
resolute

not-affected

1:2.4.2+dfsg1-3ubuntu2

Показывать по

EPSS

Процентиль: 51%
0.00703
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
6 месяцев назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
nvd
6 месяцев назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
debian
6 месяцев назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL in ...

CVSS3: 7.5
redos
2 месяца назад

Уязвимость dovecot

CVSS3: 7.5
github
6 месяцев назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

EPSS

Процентиль: 51%
0.00703
Низкий

7.5 High

CVSS3