PT-2025-54919 · Dovecot+4 · Dovecot+4
CVE-2025-59032
·
Publicado
2025-01-01
·
Atualizado
2026-07-07
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Dovecot versions prior to 2.4.3
Description
A flaw exists in the ManageSieve AUTHENTICATE command that causes the service to crash when a literal value is used as the SASL initial response. This can lead to repeated crashes, resulting in a denial of service by making the ManageSieve service unavailable to other users. No publicly available exploits are known at this time.
Recommendations
Upgrade to version 2.4.3 or later.
Restrict access to the ManageSieve port.
Disable the ManageSieve service if it is not required.
Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dovecot
Linuxmint
Red Os
Rocky Linux
Ubuntu