In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dovecot | Dovecot | * | 2.3.9.2 (excluding) |
Dovecot | Ubuntu | trusty | * |
Dovecot | Ubuntu | upstream | * |