In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Dovecot | Dovecot | * | 2.3.10.1 (excluding) |
| Red Hat Enterprise Linux 8 | RedHat | dovecot-1:2.3.8-2.el8_2.1 | * |
| Dovecot | Ubuntu | devel | * |
| Dovecot | Ubuntu | eoan | * |
| Dovecot | Ubuntu | esm-infra/focal | * |
| Dovecot | Ubuntu | focal | * |
| Dovecot | Ubuntu | trusty | * |