PT-2025-54918 · Fts Tika+4 · Fts Tika+4
CVE-2025-59031
·
Publicado
2025-01-01
·
Atualizado
2026-07-07
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Dovecot versions prior to 2.4.3
Description
Dovecot includes a script for converting attachments to text that improperly handles zip-style attachments. An attacker could leverage specially crafted OOXML documents to cause unintended files on the system to be indexed, potentially leading to their inclusion in Full-Text Search (FTS) indexes. The issue relates to the unsafe handling of zip-style attachments during the attachment-to-text conversion process. No publicly available exploits are known at this time.
Recommendations
Do not use the provided script for attachment to text conversion. Instead, utilize an alternative solution such as FTS tika.
Exploit
Correção
Allocation of Resources Without Limits
Improper Authentication
Resource Exhaustion
Information Disclosure
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dovecot
Fts Tika
Linuxmint
Red Os
Ubuntu