cbcvebase.
CVE-2024-23185
published 2024-09-10

CVE-2024-23185: Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.28%
67.1th percentile
Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long header line, or a single header split into multiple lines. This bug exists in all Dovecot versions. Incoming mails typically have some size limits set by MTA, so even largest possible header size may still fit into Dovecot's vsz_limit. So attackers probably can't DoS a victim user this way. A user could APPEND larger mails though, allowing them to DoS themselves (although maybe cause some memory issues for the backend in general). One can implement restrictions on headers on MTA component preceding Dovecot. No publicly available exploits are known.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:2.3.19.1+dfsg1-2.1+deb12u1 (bookworm)dovecot 1:2.3.19.1+dfsg1-2.1+deb12u1 (bookworm)
dovecotdovecot>= 0 < 1:2.3.13+dfsg1-2+deb11u21:2.3.13+dfsg1-2+deb11u2
dovecotdovecot>= 0 < 1:2.3.19.1+dfsg1-2.1+deb12u11:2.3.19.1+dfsg1-2.1+deb12u1
dovecotdovecot>= 0 < 1:2.3.21.1+dfsg1-11:2.3.21.1+dfsg1-1
dovecotdovecot>= 0 < 1:2.3.21.1+dfsg1-11:2.3.21.1+dfsg1-1
dovecotdovecot>= 0 < 1:2.3.7.2-1ubuntu3.71:2.3.7.2-1ubuntu3.7
dovecotdovecot>= 0 < 1:2.3.16+dfsg1-3ubuntu2.41:2.3.16+dfsg1-3ubuntu2.4
dovecotdovecot>= 0 < 1:2.3.21+dfsg1-2ubuntu61:2.3.21+dfsg1-2ubuntu6
open-xchange_gmbhox_dovecot_pro<= 2.3.21

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.