Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails. Upgrade to latest released version. No publicly available exploits are known.
History

Fri, 06 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Sep 2024 15:15:00 +0000

Type Values Removed Values Added
Description Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails. Upgrade to latest released version. No publicly available exploits are known.
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OX

Published: 2024-09-06T15:02:48.487Z

Updated: 2024-09-06T15:28:02.638Z

Reserved: 2024-02-08T08:15:37.204Z

Link: CVE-2024-25584

cve-icon Vulnrichment

Updated: 2024-09-06T15:27:57.687Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-06T15:15:12.950

Modified: 2024-09-06T16:46:26.830

Link: CVE-2024-25584

cve-icon Redhat

No data.