CVE-2019-19722
published 2019-12-13CVE-2019-19722: In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
2.48%
82.7th percentile
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | — | — |
| dovecot | dovecot | < 2.3.9.2 | 2.3.9.2 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.2-r0 | 2.3.9.2-r0 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dovecot: null pointer dereference in push notification driver
vendor_redhat·2019-12-13·CVSS 5.3
CVE-2019-19722 [MEDIUM] CWE-476 dovecot: null pointer dereference in push notification driver
dovecot: null pointer dereference in push notification driver
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
Statement: The vulnerable functionality is not present in the versions of dovecot package in Red Hat Products therefore they are not affected by this flaw.
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: dovecot (Red Hat Enterprise Linux 6) - Not affected
Package: dovecot (Red Hat Enterprise Linux 7) - Not affected
Package: dovecot (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2019-19722: dovecot - In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with...
vendor_debian·2019·CVSS 5.3
CVE-2019-19722 [MEDIUM] CVE-2019-19722: dovecot - In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with...
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-cpfv-hj4g-93jr: In Dovecot before 2
ghsa_unreviewed·2022-05-24
CVE-2019-19722 [MEDIUM] CWE-476 GHSA-cpfv-hj4g-93jr: In Dovecot before 2
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
OSV
CVE-2019-19722: In Dovecot before 2
osv·2019-12-13·CVSS 5.3
CVE-2019-19722 [MEDIUM] CVE-2019-19722: In Dovecot before 2
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19722 dovecot: null pointer dereference in push notification driver [fedora-all]
bugzilla·2019-12-13·CVSS 5.3
CVE-2019-19722 [MEDIUM] CVE-2019-19722 dovecot: null pointer dereference in push notification driver [fedora-all]
CVE-2019-19722 dovecot: null pointer dereference in push notification driver [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2019-19722 dovecot: null pointer dereference in push notification driver
bugzilla·2019-12-12·CVSS 5.3
CVE-2019-19722 [MEDIUM] CVE-2019-19722 dovecot: null pointer dereference in push notification driver
CVE-2019-19722 dovecot: null pointer dereference in push notification driver
A vulnerability was found in dovecot before version 2.3.9.1 where mail with group address as sender will cause a signal 11 crash in push notification drivers. Group address as recipient can cause crash in some drivers.
Discussion:
Reference:
https://github.com/dovecot/core/compare/393a8cabf4dad893bf2ec60bf96cfde7a0c58432%5E..1307766b6f5d97341a47376657d342bcefd10f1b.patch
---
References:
https://dovecot.org/pipermail/dovecot-news/2019-December/000426.html
https://dovecot.org/pipermail/dovecot-news/2019-December/000425.html
https://dovecot.org/pipermail/dovecot-news/2019-December/000423.html
---
Created dovecot tracking bugs for this issue:
Affects: fedora-all [bug 1783256]
---
Statement:
The vulnerable
http://www.openwall.com/lists/oss-security/2019/12/13/3https://dovecot.org/list/dovecot-news/2019-December/000428.htmlhttps://dovecot.org/pipermail/dovecot-news/2019-December/000428.htmlhttps://dovecot.org/security.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OZCJ3RBA4WIYGN7SOV4TW2AIHXPZATK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PPB7PG5BM3MC5ZF2KHQ3UR7CZIO42BB/http://www.openwall.com/lists/oss-security/2019/12/13/3https://dovecot.org/list/dovecot-news/2019-December/000428.htmlhttps://dovecot.org/pipermail/dovecot-news/2019-December/000428.htmlhttps://dovecot.org/security.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OZCJ3RBA4WIYGN7SOV4TW2AIHXPZATK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PPB7PG5BM3MC5ZF2KHQ3UR7CZIO42BB/
2019-12-13
Published