CVE-2006-0730
published 2006-02-16CVE-2006-0730: Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified…
PriorityP413medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.63%
73.8th percentile
Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1.0.beta3-1 (bookworm) | dovecot 1.0.beta3-1 (bookworm) |
| dovecot | dovecot | >= 0 < 1.0.beta3-1 | 1.0.beta3-1 |
| dovecot | dovecot | >= 0 < 1.0.beta3-1 | 1.0.beta3-1 |
| dovecot | dovecot | >= 0 < 1.0.beta3-1 | 1.0.beta3-1 |
| dovecot | dovecot | >= 0 < 1.0.beta3-1 | 1.0.beta3-1 |
| timo_sirainen | dovecot | <= 1.0beta2 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-0730: dovecot - Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote att...
vendor_debian·2006·CVSS 5.0
CVE-2006-0730 [MEDIUM] CVE-2006-0730: dovecot - Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote att...
Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
Scope: local
bookworm: resolved (fixed in 1.0.beta3-1)
bullseye: resolved (fixed in 1.0.beta3-1)
forky: resolved (fixed in 1.0.beta3-1)
sid: resolved (fixed in 1.0.beta3-1)
trixie: resolved (fixed in 1.0.beta3-1)
Red Hat
CVE-2006-0730: Multiple unspecified vulnerabilities in Dovecot before 1
vendor_redhat·CVSS 5.0
CVE-2006-0730 [MEDIUM] CVE-2006-0730: Multiple unspecified vulnerabilities in Dovecot before 1
Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
Statement: This issue only affected Dovecot versions 1.0beta1 and 1.0beta2. Red Hat Enterprise Linux 4 shipped with an earlier version of Dovecot and is therefore not vulnerable to this issue.
GHSA
GHSA-q2g9-6wv8-pjrc: Multiple unspecified vulnerabilities in Dovecot before 1
ghsa_unreviewed·2022-05-01
CVE-2006-0730 [MEDIUM] CWE-119 GHSA-q2g9-6wv8-pjrc: Multiple unspecified vulnerabilities in Dovecot before 1
Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
OSV
CVE-2006-0730: Multiple unspecified vulnerabilities in Dovecot before 1
osv·2006-02-16·CVSS 5.0
CVE-2006-0730 [MEDIUM] CVE-2006-0730: Multiple unspecified vulnerabilities in Dovecot before 1
Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/18870http://www.dovecot.org/list/dovecot/2006-February/011367.htmlhttp://www.securityfocus.com/bid/16672http://www.vupen.com/english/advisories/2006/0549https://exchange.xforce.ibmcloud.com/vulnerabilities/24709http://secunia.com/advisories/18870http://www.dovecot.org/list/dovecot/2006-February/011367.htmlhttp://www.securityfocus.com/bid/16672http://www.vupen.com/english/advisories/2006/0549https://exchange.xforce.ibmcloud.com/vulnerabilities/24709
2006-02-16
Published