Описание
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1:2.4.2+dfsg1-3ubuntu2 |
| esm-infra-legacy/trusty | needed | |
| esm-infra-legacy/xenial | needed | |
| esm-infra/bionic | needed | |
| esm-infra/focal | needed | |
| esm-infra/xenial | ignored | end of ESM support, was needed |
| jammy | released | 1:2.3.16+dfsg1-3ubuntu2.7 |
| noble | released | 1:2.3.21+dfsg1-2ubuntu6.3 |
| questing | released | 1:2.4.1+dfsg1-5ubuntu4.1 |
| resolute | not-affected | 1:2.4.2+dfsg1-3ubuntu2 |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
Attacker can send a specifically crafted message before authentication ...
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
EPSS
7.5 High
CVSS3