CVE Vulnerabilities

CVE-2020-12100

Uncontrolled Recursion

Published: Aug 12, 2020 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

Name Vendor Start Version End Version
Dovecot Dovecot * 2.3.11.3 (excluding)
Red Hat Enterprise Linux 7 RedHat dovecot-1:2.2.36-6.el7_8.1 *
Red Hat Enterprise Linux 8 RedHat dovecot-1:2.3.8-2.el8_2.2 *
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions RedHat dovecot-1:2.2.36-5.el8_0.3 *
Red Hat Enterprise Linux 8.1 Extended Update Support RedHat dovecot-1:2.2.36-10.el8_1.2 *
Dovecot Ubuntu bionic *
Dovecot Ubuntu devel *
Dovecot Ubuntu focal *
Dovecot Ubuntu precise/esm *
Dovecot Ubuntu trusty *
Dovecot Ubuntu trusty/esm *
Dovecot Ubuntu upstream *
Dovecot Ubuntu xenial *

Potential Mitigations

References