PT-2026-83054 · Dovecot · Dovecot
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
dovecot versions prior to 2.4.5-1.1
Description
Mail content stored by a user can be crafted to be interpreted as dsync protocol commands when an administrator executes dsync using the stream protocol, such as during migration or replication. This allows for the modification of mailbox states on the destination, including internal mailbox attributes that users should not be able to set directly, and may result in dsync errors.
Recommendations
Update to version 2.4.5-1.1.
Avoid running dsync with the stream protocol on mailboxes containing untrusted content.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovecot