PT-2025-54918 · Fts Tika+4 · Fts Tika+4
CVE-2025-59031
·
Published
2025-01-01
·
Updated
2026-07-07
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Dovecot versions prior to 2.4.3
Description
Dovecot includes a script for converting attachments to text that improperly handles zip-style attachments. An attacker could leverage specially crafted OOXML documents to cause unintended files on the system to be indexed, potentially leading to their inclusion in Full-Text Search (FTS) indexes. The issue relates to the unsafe handling of zip-style attachments during the attachment-to-text conversion process. No publicly available exploits are known at this time.
Recommendations
Do not use the provided script for attachment to text conversion. Instead, utilize an alternative solution such as FTS tika.
Exploit
Fix
Allocation of Resources Without Limits
Improper Authentication
Resource Exhaustion
Information Disclosure
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dovecot
Fts Tika
Linuxmint
Red Os
Ubuntu