CVE-2019-10691
published 2019-04-24CVE-2019-10691: The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.80%
85.0th percentile
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.3.4.1-4 (bookworm) | dovecot 1:2.3.4.1-4 (bookworm) |
| dovecot | dovecot | < 2.3.5.2 | 2.3.5.2 |
| dovecot | dovecot | >= 0 < 1:2.3.4.1-4 | 1:2.3.4.1-4 |
| dovecot | dovecot | >= 0 < 1:2.3.4.1-4 | 1:2.3.4.1-4 |
| dovecot | dovecot | >= 0 < 1:2.3.4.1-4 | 1:2.3.4.1-4 |
| dovecot | dovecot | >= 0 < 1:2.3.4.1-4 | 1:2.3.4.1-4 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7m29-wr8r-5c2m: The JSON encoder in Dovecot before 2
ghsa_unreviewed·2022-05-24
CVE-2019-10691 [HIGH] GHSA-7m29-wr8r-5c2m: The JSON encoder in Dovecot before 2
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
OSV
CVE-2019-10691: The JSON encoder in Dovecot before 2
osv·2019-04-24·CVSS 7.5
CVE-2019-10691 [HIGH] CVE-2019-10691: The JSON encoder in Dovecot before 2
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
Ubuntu
Dovecot vulnerability
vendor_ubuntu·2019-04-23
CVE-2019-10691 Dovecot vulnerability
Title: Dovecot vulnerability
Summary: Dovecot could be made to crash if it received specially crafted network
traffic.
It was discovered that the Dovecot JSON encoder incorrectly handled certain
invalid UTF-8 characters. A remote attacker could possibly use this issue
to cause Dovecot to repeatedly crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack.
vendor_redhat·2019-04-18·CVSS 7.5
CVE-2019-10691 [HIGH] CWE-228 dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack.
dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack.
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
Statement: A flaw was found in the JSON encoder in dovecot, which an attacker could use to crash the application via usage of invalid UTF-8 characters in the login name during authentication or by using invalid UTF-8 sequence in email when OX push notification driver is enabled. The versions of dovecot shipped with Red Hat Enterprise Linux did not ship the vulnerable code and therefore were not affected by this flaw.
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: dovecot (Red Hat Enterpris
Debian
CVE-2019-10691: dovecot - The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash ...
vendor_debian·2019·CVSS 7.5
CVE-2019-10691 [HIGH] CVE-2019-10691: dovecot - The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash ...
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
Scope: local
bookworm: resolved (fixed in 1:2.3.4.1-4)
bullseye: resolved (fixed in 1:2.3.4.1-4)
forky: resolved (fixed in 1:2.3.4.1-4)
sid: resolved (fixed in 1:2.3.4.1-4)
trixie: resolved (fixed in 1:2.3.4.1-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10691 dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack. [fedora-all]
bugzilla·2019-04-18·CVSS 7.5
CVE-2019-10691 [HIGH] CVE-2019-10691 dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack. [fedora-all]
CVE-2019-10691 dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
Bugzilla
CVE-2019-10691 dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack.
bugzilla·2019-04-18·CVSS 7.5
CVE-2019-10691 [HIGH] CVE-2019-10691 dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack.
CVE-2019-10691 dovecot: Mishandling invalid UTF-8 characters by JSON encoder leading to possible DoS attack.
JSON encoder in Dovecot 2.3 incorrecty assert-crashes when encountering invalid UTF-8 characters. Attacker can repeatedly crash Dovecot authentication process by logging in using invalid UTF-8 sequence in username. Crash can also occur if OX push notification driver is enabled and an email is delivered with invalid UTF-8 sequence in From or Subject header.
External References:
https://dovecot.org/list/dovecot-news/2019-April/000406.html
Discussion:
Created dovecot tracking bugs for this issue:
Affects: fedora-all [bug 1701218]
---
Upstream commit: https://github.com/dovecot/core/commit/973769d74433de3c56c4ffdf4f343cb35d98e4f7
---
Statement:
A flaw was found in the JSON enc
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00000.htmlhttp://www.openwall.com/lists/oss-security/2019/04/18/3https://dovecot.org/list/dovecot-news/2019-April/000406.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHFZ5OWRIZGIWZJ5PTNVWWZNLLNH4XYS/https://security.gentoo.org/glsa/201908-29http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00000.htmlhttp://www.openwall.com/lists/oss-security/2019/04/18/3https://dovecot.org/list/dovecot-news/2019-April/000406.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHFZ5OWRIZGIWZJ5PTNVWWZNLLNH4XYS/https://security.gentoo.org/glsa/201908-29
2019-04-24
Published