Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-27858

Опубликовано: 27 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

РелизСтатусПримечание
devel

not-affected

1:2.4.2+dfsg1-3ubuntu2
esm-infra-legacy/trusty

needed

esm-infra-legacy/xenial

needed

esm-infra/bionic

needed

esm-infra/focal

needed

esm-infra/xenial

ignored

end of ESM support, was needed
jammy

released

1:2.3.16+dfsg1-3ubuntu2.7
noble

released

1:2.3.21+dfsg1-2ubuntu6.3
questing

released

1:2.4.1+dfsg1-5ubuntu4.1
resolute

not-affected

1:2.4.2+dfsg1-3ubuntu2

Показывать по

EPSS

Процентиль: 52%
0.0079
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
4 месяца назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
nvd
4 месяца назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
debian
4 месяца назад

Attacker can send a specifically crafted message before authentication ...

CVSS3: 7.5
github
4 месяца назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

rocky
2 месяца назад

Important: dovecot security update

EPSS

Процентиль: 52%
0.0079
Низкий

7.5 High

CVSS3