In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.
References
Link | Resource |
---|---|
https://www.dovecot.org/security.html | Vendor Advisory |
https://www.dovecot.org/download.html | Product |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4XLI55NGRDTGMVOPYFCPPFNPA5VKYSSY/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QHFZ5OWRIZGIWZJ5PTNVWWZNLLNH4XYS/ | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00026.html | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00024.html | Mailing List Third Party Advisory |
Configurations
Information
Published : 2019-05-08 10:29
Updated : 2023-03-01 07:20
NVD link : CVE-2019-11499
Mitre link : CVE-2019-11499
JSON object : View
CWE
Products Affected
dovecot
- dovecot
fedoraproject
- fedora
opensuse
- leap