CVE Vulnerabilities

CVE-2020-12100

Uncontrolled Recursion

Published: Aug 12, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

NameVendorStart VersionEnd Version
DovecotDovecot*2.3.11.3 (excluding)
Red Hat Enterprise Linux 7RedHatdovecot-1:2.2.36-6.el7_8.1*
Red Hat Enterprise Linux 8RedHatdovecot-1:2.3.8-2.el8_2.2*
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsRedHatdovecot-1:2.2.36-5.el8_0.3*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatdovecot-1:2.2.36-10.el8_1.2*
DovecotUbuntubionic*
DovecotUbuntudevel*
DovecotUbuntuesm-infra-legacy/trusty*
DovecotUbuntuesm-infra/bionic*
DovecotUbuntuesm-infra/focal*
DovecotUbuntuesm-infra/xenial*
DovecotUbuntufocal*
DovecotUbuntuprecise/esm*
DovecotUbuntutrusty*
DovecotUbuntutrusty/esm*
DovecotUbuntuupstream*
DovecotUbuntuxenial*

Potential Mitigations

References