CVE-2011-1929Improper Input Validation in Dovecot

Severity
5.0MEDIUMNVD
EPSS
6.5%
top 8.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 24
Latest updateMay 17

Description

lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/dovecot< dovecot 1:2.0.13-1 (bookworm)
Debiandovecot/dovecot< 1:2.0.13-1+3
NVDdovecot/dovecot31 versions+30

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8hm3-4p5h-mv6g: lib-mail/message-header-parser2022-05-17
OSV
CVE-2011-1929: lib-mail/message-header-parser2011-05-24

📋Vendor Advisories

3
Ubuntu
Dovecot vulnerability2011-06-02
Red Hat
dovecot: potential crash when parsing header names that contain NUL characters2011-05-11
Debian
CVE-2011-1929: dovecot - lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before...2011

💬Community

2
Bugzilla
CVE-2011-1929 CVE-2011-2166 CVE-2011-2167 dovecot various flaws [fedora-all]2011-05-30
Bugzilla
CVE-2011-1929 dovecot: potential crash when parsing header names that contain NUL characters2011-05-19