PT-2026-28366 · Dovecot+4 · Dovecot+4
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Dovecot versions prior to 2.4.3
Description
An attacker can send a crafted message before authentication, leading to excessive memory allocation within the managesieve component. This can cause the
managesieve-login process to crash, potentially resulting in a denial-of-service condition. No publicly available exploits are currently known.Recommendations
Update to version 2.4.3 or later. Protect access to the managesieve protocol.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dovecot
Linuxmint
Red Os
Rocky Linux
Ubuntu