Description
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2517-1 | dovecot security update |
Debian DSA |
DSA-4825-1 | dovecot security update |
EUVD |
EUVD-2020-17118 | An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure). |
Ubuntu USN |
USN-4674-1 | Dovecot vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:12:08.740Z
Reserved: 2020-08-19T00:00:00.000Z
Link: CVE-2020-24386
No data.
Status : Modified
Published: 2021-01-04T17:15:13.867
Modified: 2024-11-21T05:14:43.127
Link: CVE-2020-24386
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN