CVE-2024-23184
published 2024-09-10CVE-2024-23184: Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds…
PriorityP427medium5CVSS 3.1
AVNACLPRLUINSCCNILAN
EPSS
0.84%
54.1th percentile
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.3.19.1+dfsg1-2.1+deb12u1 (bookworm) | dovecot 1:2.3.19.1+dfsg1-2.1+deb12u1 (bookworm) |
| dovecot | dovecot | >= 0 < 1:2.3.13+dfsg1-2+deb11u2 | 1:2.3.13+dfsg1-2+deb11u2 |
| dovecot | dovecot | >= 0 < 1:2.3.19.1+dfsg1-2.1+deb12u1 | 1:2.3.19.1+dfsg1-2.1+deb12u1 |
| dovecot | dovecot | >= 0 < 1:2.3.21.1+dfsg1-1 | 1:2.3.21.1+dfsg1-1 |
| dovecot | dovecot | >= 0 < 1:2.3.21.1+dfsg1-1 | 1:2.3.21.1+dfsg1-1 |
| dovecot | dovecot | >= 0 < 1:2.3.7.2-1ubuntu3.7 | 1:2.3.7.2-1ubuntu3.7 |
| dovecot | dovecot | >= 0 < 1:2.3.16+dfsg1-3ubuntu2.4 | 1:2.3.16+dfsg1-3ubuntu2.4 |
| dovecot | dovecot | >= 0 < 1:2.3.21+dfsg1-2ubuntu6 | 1:2.3.21+dfsg1-2ubuntu6 |
| open-xchange_gmbh | ox_dovecot_pro | <= 2.3.21 | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2024-09-16·CVSS 5.0
CVE-2024-23184 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
It was discovered that Dovecot incorrectly handled a large number of
address headers. A remote attacker could possibly use this issue to cause
Dovecot to consume resources, leading to a denial of service.
(CVE-2024-23184)
It was discovered that Dovecot incorrectly handled very large headers. A
remote attacker could possibly use this issue to cause Dovecot to consume
resources, leading to a denial of service. (CVE-2024-23185)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2024-09-02·CVSS 5.0
CVE-2024-23184 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
It was discovered that Dovecot did not not properly have restrictions on
ithe size of address headers. A remote attacker could possibly use this
issue to cause denial of service. (CVE-2024-23184, CVE-2024-23185)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dovecot: using a large number of address headers may trigger a denial of service
vendor_redhat·2024-08-15·CVSS 5.0
CVE-2024-23184 [MEDIUM] CWE-770 dovecot: using a large number of address headers may trigger a denial of service
dovecot: using a large number of address headers may trigger a denial of service
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.
A flaw was found in Dovecot. Processing a large number of address headers (From, To, Cc, Bcc, etc) can be excessively CPU intens
Debian
CVE-2024-23184: dovecot - Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes exces...
vendor_debian·2024·CVSS 5.0
CVE-2024-23184 [MEDIUM] CVE-2024-23184: dovecot - Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes exces...
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.
Scope: local
bookworm: resolved (fixed in 1:2.3.19.1+dfsg1-2.1+deb12u1)
bullseye: resolved (fixed in 1:2.3.13+dfsg1-2+deb11u2)
forky: resolved (fixed in 1:2.3.21.1+dfsg1-1)
sid: resolved (fixed in 1:2.3.21.1+dfs
OSV
dovecot vulnerabilities
osv·2024-09-16·CVSS 5.0
CVE-2024-23184 [MEDIUM] dovecot vulnerabilities
dovecot vulnerabilities
It was discovered that Dovecot incorrectly handled a large number of
address headers. A remote attacker could possibly use this issue to cause
Dovecot to consume resources, leading to a denial of service.
(CVE-2024-23184)
It was discovered that Dovecot incorrectly handled very large headers. A
remote attacker could possibly use this issue to cause Dovecot to consume
resources, leading to a denial of service. (CVE-2024-23185)
OSV
CVE-2024-23184: Having a large number of address headers (From, To, Cc, Bcc, etc
osv·2024-09-10·CVSS 5.0
CVE-2024-23184 [MEDIUM] CVE-2024-23184: Having a large number of address headers (From, To, Cc, Bcc, etc
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.
GHSA
GHSA-5f48-j349-fj3m: Having a large number of address headers (From, To, Cc, Bcc, etc
ghsa_unreviewed·2024-09-10
CVE-2024-23184 [MEDIUM] CWE-770 GHSA-5f48-j349-fj3m: Having a large number of address headers (From, To, Cc, Bcc, etc
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.
OSV
dovecot vulnerabilities
osv·2024-09-02·CVSS 5.0
CVE-2024-23184 [MEDIUM] dovecot vulnerabilities
dovecot vulnerabilities
It was discovered that Dovecot did not not properly have restrictions on
ithe size of address headers. A remote attacker could possibly use this
issue to cause denial of service. (CVE-2024-23184, CVE-2024-23185)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-10
Published