CVE-2011-1929
published 2011-05-24CVE-2011-1929: lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.25%
87.0th percentile
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.0.13-1 (bookworm) | dovecot 1:2.0.13-1 (bookworm) |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
| dovecot | dovecot | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8hm3-4p5h-mv6g: lib-mail/message-header-parser
ghsa_unreviewed·2022-05-17
CVE-2011-1929 [MEDIUM] CWE-20 GHSA-8hm3-4p5h-mv6g: lib-mail/message-header-parser
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
OSV
CVE-2011-1929: lib-mail/message-header-parser
osv·2011-05-24·CVSS 5.0
CVE-2011-1929 [MEDIUM] CVE-2011-1929: lib-mail/message-header-parser
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
Ubuntu
Dovecot vulnerability
vendor_ubuntu·2011-06-02
CVE-2011-1929 Dovecot vulnerability
Title: Dovecot vulnerability
Summary: An attacker could send a crafted email message that could disrupt email
service.
It was discovered that the message header parser in Dovecot did not
properly handle '\0' characters in header names. This could allow a
remote attacker to cause a denial of service through a crafted email
message by crashing the Dovecot daemon or corrupting mailboxes.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dovecot: potential crash when parsing header names that contain NUL characters
vendor_redhat·2011-05-11·CVSS 5.0
CVE-2011-1929 [MEDIUM] dovecot: potential crash when parsing header names that contain NUL characters
dovecot: potential crash when parsing header names that contain NUL characters
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
Debian
CVE-2011-1929: dovecot - lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before...
vendor_debian·2011·CVSS 5.0
CVE-2011-1929 [MEDIUM] CVE-2011-1929: dovecot - lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before...
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
Scope: local
bookworm: resolved (fixed in 1:2.0.13-1)
bullseye: resolved (fixed in 1:2.0.13-1)
forky: resolved (fixed in 1:2.0.13-1)
sid: resolved (fixed in 1:2.0.13-1)
trixie: resolved (fixed in 1:2.0.13-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1929 CVE-2011-2166 CVE-2011-2167 dovecot various flaws [fedora-all]
bugzilla·2011-05-30·CVSS 5.0
CVE-2011-1929 [MEDIUM] CVE-2011-1929 CVE-2011-2166 CVE-2011-2167 dovecot various flaws [fedora-all]
CVE-2011-1929 CVE-2011-2166 CVE-2011-2167 dovecot various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=706286
Please note: this issue affects multip
Bugzilla
CVE-2011-1929 dovecot: potential crash when parsing header names that contain NUL characters
bugzilla·2011-05-19·CVSS 5.0
CVE-2011-1929 [MEDIUM] CVE-2011-1929 dovecot: potential crash when parsing header names that contain NUL characters
CVE-2011-1929 dovecot: potential crash when parsing header names that contain NUL characters
Dovecot has released version 1.2.17 [1] and 2.0.13 [2] to address a potential crash, and possibly mailbox corruption, when dovecot parsed header names that contained NUL characters. This was due to a pointer possibly pointing past allocated memory. An upstream patch [3] is available.
[1] http://dovecot.org/pipermail/dovecot/2011-May/059086.html
[2] http://dovecot.org/pipermail/dovecot/2011-May/059085.html
[3] http://hg.dovecot.org/dovecot-1.1/rev/3698dfe0f21c
Discussion:
dovecot 1.2.17 for Fedora 13 has been just submitted for updates-testing, 2.0.13 versions for Fedora 14+ are already in updatest-testing repository.
https://admin.fedoraproject.org/updates/dovecot-1.2.17-1.fc13
https://admin.
http://dovecot.org/pipermail/dovecot/2011-May/059085.htmlhttp://dovecot.org/pipermail/dovecot/2011-May/059086.htmlhttp://hg.dovecot.org/dovecot-1.1/rev/3698dfe0f21chttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061384.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-May/060815.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-May/060825.htmlhttp://openwall.com/lists/oss-security/2011/05/18/4http://openwall.com/lists/oss-security/2011/05/19/3http://openwall.com/lists/oss-security/2011/05/19/6http://osvdb.org/72495http://secunia.com/advisories/44683http://secunia.com/advisories/44712http://secunia.com/advisories/44756http://secunia.com/advisories/44771http://secunia.com/advisories/44827http://www.debian.org/security/2011/dsa-2252http://www.dovecot.org/doc/NEWS-1.2http://www.dovecot.org/doc/NEWS-2.0http://www.mandriva.com/security/advisories?name=MDVSA-2011:101http://www.redhat.com/support/errata/RHSA-2011-1187.htmlhttp://www.securityfocus.com/bid/47930http://www.ubuntu.com/usn/USN-1143-1https://bugzilla.redhat.com/show_bug.cgi?id=706286https://exchange.xforce.ibmcloud.com/vulnerabilities/67589https://hermes.opensuse.org/messages/8581790http://dovecot.org/pipermail/dovecot/2011-May/059085.htmlhttp://dovecot.org/pipermail/dovecot/2011-May/059086.htmlhttp://hg.dovecot.org/dovecot-1.1/rev/3698dfe0f21chttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061384.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-May/060815.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-May/060825.htmlhttp://openwall.com/lists/oss-security/2011/05/18/4http://openwall.com/lists/oss-security/2011/05/19/3http://openwall.com/lists/oss-security/2011/05/19/6http://osvdb.org/72495http://secunia.com/advisories/44683http://secunia.com/advisories/44712http://secunia.com/advisories/44756http://secunia.com/advisories/44771http://secunia.com/advisories/44827http://www.debian.org/security/2011/dsa-2252http://www.dovecot.org/doc/NEWS-1.2http://www.dovecot.org/doc/NEWS-2.0http://www.mandriva.com/security/advisories?name=MDVSA-2011:101http://www.redhat.com/support/errata/RHSA-2011-1187.htmlhttp://www.securityfocus.com/bid/47930http://www.ubuntu.com/usn/USN-1143-1https://bugzilla.redhat.com/show_bug.cgi?id=706286https://exchange.xforce.ibmcloud.com/vulnerabilities/67589https://hermes.opensuse.org/messages/8581790
2011-05-24
Published