Impact
An attacker who can send mail to a mailbox can craft a message whose headers contain a very large number of email addresses or MIME parameters. When the message is read over IMAP, the parser consumes excessive memory, exhausting the process limit and causing it to terminate. The mail is still delivered, but the affected user experiences a denial of service whenever they attempt to access or read the message.
Affected Systems
The vulnerability affects Open‑Xchange GmbH's OX Dovecot CE and OX Dovecot Pro mail servers. No specific vulnerable versions are listed, so any installation of these products that has not received the vendor‑supplied fix is considered affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk. The exploit requires the adversary to be able to deliver mail to the target mailbox, which is typically possible over the Internet if the server accepts inbound messages. Denial occurs only when the message is read, meaning attackers can trigger a crash by merely sending the crafted email. No publicly available exploits are known, and the EPSS score is < 1%, so the likelihood of widespread exploitation is low, but the denial of service could be useful in a targeted or local disruption scenario.
OpenCVE Enrichment