Search CVE reports
1 – 10 of 105 results
imap-login crash: Self-recursion on zero-output decompress chunks. An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash.
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
auth: db-oauth2: aud claim used as fallback for missing scope claim. An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
IMAP: COMPRESS ZSTD can cause excessive memory usage. An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Sieve resource usage tracking lost when active script changes. Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Single NUL-Byte XCLIENT FORWARD Payload Crashes. A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt.
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
doveadm_password or api key length can still be leaked with timing comparisons. The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret.
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
imap-urlauth leaks memory into user-visible error messages. An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client.
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
imap: Pre-login memory/CPU growth with ID command. An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately.
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
XCLIENT FORWARD=3D bare token not namespaced, allows nopassword injection via trusted proxy. Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Sieve editheader RCE. An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |