PT-2026-64004 · Dovecot · Dovecot
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
dovecot versions prior to 2.4.5-1.1
Description
An attacker with valid credentials can cause a denial of service for IMAP by selecting a compression algorithm for the connection that requires excessive memory for its decompression state. By opening several such connections, the process memory limit is reached, resulting in the termination of the process and all associated connections.
Recommendations
Update to version 2.4.5-1.1.
Disable IMAP compression.
Limit the number of connections handled by a single imap-login process.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovecot