The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dovecot | Dovecot | * | 2.3.5.2 (excluding) |
Dovecot | Ubuntu | cosmic | * |
Dovecot | Ubuntu | devel | * |
Dovecot | Ubuntu | disco | * |
Dovecot | Ubuntu | upstream | * |