Impact
An attacker with valid credentials can submit a Sieve script that uses the editheader extension, triggering a use‑after‑free in the mail editing code. This misuse allows memory contents to be written beyond the intended buffer, leaking information and creating an opportunity for memory corruption during delivery, which can crash the process or lead to execution of arbitrary code in the mail delivery context. The flaw is based on improper memory management.
Affected Systems
The vulnerability affects Open‑Xchange GmbH's OX Dovecot CE and OX Dovecot Pro products. No specific version numbers are listed in the advisory, so all currently deployed instances should be treated as potentially impacted until an update is applied.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, and the EPSS score is 0.00288 (0.288%). The vulnerability is not listed in the CISA KEV catalog and no public exploits have been reported. However, the weakness requires legitimate user credentials, implying that an authenticated user could craft the malicious Sieve script. Once executed, the application could crash or be hijacked for arbitrary code. The high CVSS weight combined with the low levels of exploitation probability and lack of mitigation unless patched elevates the risk significantly.
OpenCVE Enrichment