Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.142825
Category:General
Title:Dovecot < 2.2.36.4 and < 2.3.7.2 Heap Overflow Vulnerability
Summary:Dovecot is prone to an unauthenticated heap out of bounds heap memory write; vulnerability.
Description:Summary:
Dovecot is prone to an unauthenticated heap out of bounds heap memory write
vulnerability.

Vulnerability Insight:
This vulnerability allows for out-of-bounds writes to objects stored on the
heap up to 8096 bytes in pre-login phase, and 65536 bytes post-login phase, allowing sufficiently skilled
attacker to perform complicated attacks that can lead to leaking private information or remote code execution.
Abuse of this bug is very difficult to observe, as it does not necessarily cause a crash. Attempts to abuse this
bug are not directly evident from logs.

Affected Software/OS:
Dovecot prior to version 2.2.36.4 and 2.3.x prior to version 2.3.7.2.

Solution:
Update to version 2.2.36.4, 2.3.7.2 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-11500
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3GYTZLLDNIFWT7D7JSB25ERJNMOR4CQ3/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KVHY3MU2OK2EWZJFGNDSAOMD42L7DFPX/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YSJVVVRAE3SITC2ZLGCPMFDN3WVYZBWF/
https://security.gentoo.org/glsa/201908-29
https://www.dovecot.org/security.html
https://lists.debian.org/debian-lts-announce/2019/08/msg00035.html
RedHat Security Advisories: RHSA-2019:2822
https://access.redhat.com/errata/RHSA-2019:2822
RedHat Security Advisories: RHSA-2019:2836
https://access.redhat.com/errata/RHSA-2019:2836
RedHat Security Advisories: RHSA-2019:2885
https://access.redhat.com/errata/RHSA-2019:2885
SuSE Security Announcement: openSUSE-SU-2019:2278 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00024.html
SuSE Security Announcement: openSUSE-SU-2019:2281 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00026.html
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.