CVE-2019-11500

Published: 28 August 2019

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

Priority

High

CVSS 3 base score: 9.8

Status

Package Release Status
dovecot
Launchpad, Ubuntu, Debian
Upstream
Released (2.3.7.2,2.2.36.4)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (1:2.2.33.2-1ubuntu4.4)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (1:2.2.22-1ubuntu2.11)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (1:2.2.9-1ubuntu2.6+esm1)