Your submission was sent successfully! Close

CVE-2020-12100

Published: 12 August 2020

In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.

Notes

AuthorNote
leosilva
marking precise as ignored since we won't fix it
version in that release is quite old and the backports
could possibly cause serious regressions.
Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
dovecot
Launchpad, Ubuntu, Debian
bionic
Released (1:2.2.33.2-1ubuntu4.6)
focal
Released (1:2.3.7.2-1ubuntu3.2)
precise Ignored

trusty
Released (1:2.2.9-1ubuntu2.6+esm3)
upstream
Released (2.3.11)
xenial
Released (1:2.2.22-1ubuntu2.13)