Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 20 of 62 results


CVE-2020-12673

Medium priority
Fixed

In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Fixed Fixed Fixed
Show less packages

CVE-2020-12100

Medium priority
Fixed

In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Fixed Fixed Fixed
Show less packages

CVE-2020-10967

Medium priority
Fixed

In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Fixed Not affected Not affected
Show less packages

CVE-2020-10958

Medium priority
Fixed

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Fixed Not affected Not affected
Show less packages

CVE-2020-10957

Medium priority
Fixed

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Fixed Not affected Not affected
Show less packages

CVE-2020-7957

Medium priority
Not affected

The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the...

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Not affected Not affected
Show less packages

CVE-2020-7046

Medium priority
Not affected

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Not affected Not affected
Show less packages

CVE-2019-19722

Medium priority
Not affected

In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or...

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Not affected Not affected
Show less packages

CVE-2016-4983

Medium priority
Not affected

A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Not affected
Show less packages

CVE-2019-11500

High priority
Fixed

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and...

1 affected packages

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dovecot Fixed Fixed
Show less packages