Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2019-19722

Published: 13 December 2019

In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.

Notes

AuthorNote
alexmurray
Only affects 2.3.9 according to upstream - original fix was incomplete so required extra fix in 2.3.9.2 release

Mitigation

Disable push notifications

Priority

Medium

Cvss 3 Severity Score

5.3

Score breakdown

Status

Package Release Status
dovecot
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(1:2.2.33.2-1ubuntu4.5)
disco Not vulnerable
(1:2.3.4.1-1ubuntu2.4)
eoan Not vulnerable
(1:2.3.4.1-5ubuntu3)
trusty Not vulnerable
(1:2.2.9-1ubuntu2.6)
upstream
Released (2.3.9.2)
xenial Not vulnerable
(1:2.2.22-1ubuntu2.12)
Patches:
upstream: https://github.com/dovecot/core/commit/393a8cabf4dad893bf2ec60bf96cfde7a0c58432
upstream: https://github.com/dovecot/core/commit/1307766b6f5d97341a47376657d342bcefd10f1b
upstream: https://github.com/dovecot/core/commit/82c948db496cdc2d25b40eb8613c1eaa5c622384

Severity score breakdown

Parameter Value
Base score 5.3
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact Low
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L