CVE-2020-12100Uncontrolled Recursion in Dovecot

Severity
7.5HIGHNVD
EPSS
19.6%
top 4.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 24

Description

In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDdovecot/dovecot< 2.3.11.3
Debiandovecot/dovecot< 1:2.3.11.3+dfsg1-1+3
Ubuntudovecot/dovecot< 1:2.2.22-1ubuntu2.13+3

Also affects: Debian Linux 10.0, 9.0, Fedora 31, 32, 33, Ubuntu Linux 14.04, 16.04, 18.04, 20.04

🔴Vulnerability Details

5
GHSA
GHSA-pq8h-22gg-vpmw: In Dovecot before 22022-05-24
OSV
dovecot vulnerabilities2020-08-17
OSV
dovecot vulnerabilities2020-08-12
OSV
CVE-2020-12100: In Dovecot before 22020-08-12
CVEList
CVE-2020-12100: In Dovecot before 22020-08-12

📋Vendor Advisories

4
Ubuntu
Dovecot vulnerabilities2020-08-17
Ubuntu
Dovecot vulnerabilities2020-08-12
Red Hat
dovecot: Resource exhaustion via deeply nested MIME parts2020-08-12
Debian
CVE-2020-12100: dovecot - In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda ...2020

💬Community

2
Bugzilla
CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts [fedora-all]2020-08-13
Bugzilla
CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts2020-08-05
CVE-2020-12100 — Uncontrolled Recursion in Dovecot | cvebase