Description
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1901-1 | dovecot security update |
Debian DSA |
DSA-4510-1 | dovecot security update |
Ubuntu USN |
USN-4110-1 | Dovecot vulnerability |
Ubuntu USN |
USN-4110-2 | Dovecot vulnerability |
Ubuntu USN |
USN-4110-3 | Dovecot regression |
Ubuntu USN |
USN-4110-4 | Dovecot regression |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:55:40.604Z
Reserved: 2019-04-24T00:00:00.000Z
Link: CVE-2019-11500
No data.
Status : Modified
Published: 2019-08-29T14:15:11.037
Modified: 2024-11-21T04:21:12.797
Link: CVE-2019-11500
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN