In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dovecot | Dovecot | * | 2.3.11.3 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | dovecot-1:2.2.36-6.el7_8.1 | * |
Red Hat Enterprise Linux 8 | RedHat | dovecot-1:2.3.8-2.el8_2.2 | * |
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | RedHat | dovecot-1:2.2.36-5.el8_0.3 | * |
Red Hat Enterprise Linux 8.1 Extended Update Support | RedHat | dovecot-1:2.2.36-10.el8_1.2 | * |
Dovecot | Ubuntu | bionic | * |
Dovecot | Ubuntu | devel | * |
Dovecot | Ubuntu | focal | * |
Dovecot | Ubuntu | precise/esm | * |
Dovecot | Ubuntu | trusty | * |
Dovecot | Ubuntu | trusty/esm | * |
Dovecot | Ubuntu | upstream | * |
Dovecot | Ubuntu | xenial | * |