Your submission was sent successfully! Close

CVE-2020-12674

Published: 12 August 2020

In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.

Notes

AuthorNote
leosilva
marking precise as ignored since we won't fix it
version in that release is quite old and the backports
could possibly cause serious regressions.
Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
dovecot
Launchpad, Ubuntu, Debian
bionic
Released (1:2.2.33.2-1ubuntu4.6)
focal
Released (1:2.3.7.2-1ubuntu3.2)
precise Ignored

trusty
Released (1:2.2.9-1ubuntu2.6+esm3)
upstream
Released (2.3.11)
xenial
Released (1:2.2.22-1ubuntu2.13)