CVE-2020-7046
published 2020-02-12CVE-2020-7046: lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the…
PriorityP357high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
51.26%
98.8th percentile
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | — | — |
| dovecot | dovecot | >= 0 < 2.3.10.1-r0 | 2.3.10.1-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.9.3-r0 | 2.3.9.3-r0 |
| dovecot | dovecot | >= 0 < 2.3.10.1-r0 | 2.3.10.1-r0 |
| dovecot | dovecot | >= 0 < 2.3.10.1-r0 | 2.3.10.1-r0 |
| dovecot | dovecot | >= 2.3.9 < 2.3.9.3 | 2.3.9.3 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by sending truncated UTF-8 data in SMTP command parameters to submission-login or lmtp processes in Dovecot 2.3.9 before 2.3.9.3, causing an infinite loop at 100% CPU — monitor for submission-login or lmtp processes pegged at 100% CPU as a DoS indicator. ↗
- →The attack can be triggered unauthenticated — no credentials are required to exploit this DoS condition against submission-login. ↗
- →Affected component is lib-smtp within submission-login and lmtp services in Dovecot; focus process-level monitoring on these two daemons for anomalous CPU consumption. ↗
- ·Only Dovecot versions 2.3.9 up to (but not including) 2.3.9.3 are affected; versions outside this range (including all RHEL 5/6/7/8 shipped versions) are not affected. ↗
- ·Red Hat Enterprise Linux 5, 6, 7, and 8 packages are confirmed not affected — no patching action required on those platforms. ↗
- ·The fix is available in upstream commit ed4b7d5d1b30964216d61d3090a7b47a957f5b26; patch or upgrade to Dovecot 2.3.9.3 or later to remediate. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dovecot: Attacker can cause submission-login and lmtp processes to be exhausted leading to DoS
vendor_redhat·2020-02-12·CVSS 7.5
CVE-2020-7046 [HIGH] CWE-20 dovecot: Attacker can cause submission-login and lmtp processes to be exhausted leading to DoS
dovecot: Attacker can cause submission-login and lmtp processes to be exhausted leading to DoS
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: dovecot (Red Hat Enterprise Linux 6) - Not affected
Package: dovecot (Red Hat Enterprise Linux 7) - Not affected
Package: dovecot (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2020-7046: dovecot - lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles...
vendor_debian·2020·CVSS 7.5
CVE-2020-7046 [HIGH] CVE-2020-7046: dovecot - lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles...
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-xxqf-cf9x-9rwq: lib-smtp in submission-login and lmtp in Dovecot 2
ghsa_unreviewed·2022-05-24
CVE-2020-7046 [HIGH] CWE-835 GHSA-xxqf-cf9x-9rwq: lib-smtp in submission-login and lmtp in Dovecot 2
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
OSV
CVE-2020-7046: lib-smtp in submission-login and lmtp in Dovecot 2
osv·2020-02-12·CVSS 7.5
CVE-2020-7046 [HIGH] CVE-2020-7046: lib-smtp in submission-login and lmtp in Dovecot 2
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2020/02/12/1https://dovecot.org/pipermail/dovecot-news/2020-February/000431.htmlhttps://dovecot.org/securityhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XYT55WH372BJOXCJRKBDIFGBMPVOIDT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJXHOUT3FH2DJNMACSX4GHPP4MUV4UKA/http://www.openwall.com/lists/oss-security/2020/02/12/1https://dovecot.org/pipermail/dovecot-news/2020-February/000431.htmlhttps://dovecot.org/securityhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XYT55WH372BJOXCJRKBDIFGBMPVOIDT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJXHOUT3FH2DJNMACSX4GHPP4MUV4UKA/
2020-02-12
Published