Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-24386
Description:An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker- controlled parameters, leading to access to other users' email messages (and path disclosure).
Test IDs: 1.3.6.1.4.1.25623.1.0.892517   1.3.6.1.4.1.25623.1.0.117154   1.3.6.1.4.1.25623.1.0.704825   1.3.6.1.4.1.25623.1.1.4.2021.0018.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-24386
Debian Security Information: DSA-4825 (Google Search)
https://www.debian.org/security/2021/dsa-4825
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GXDKFLOCUP7I4ELGQ2F4P5TGC6NXMYV7/
http://seclists.org/fulldisclosure/2021/Jan/18
https://security.gentoo.org/glsa/202101-01
http://packetstormsecurity.com/files/160842/Dovecot-2.3.11.3-Access-Bypass.html
https://doc.dovecot.org/configuration_manual/hibernation/
https://dovecot.org/security




© 1998-2025 E-Soft Inc. All rights reserved.