PT-2026-83062 · Dovecot · Dovecot
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
dovecot versions prior to 2.4.5-1.1
Description
When IMAP compression is enabled, the compression state is reused across responses in a session. This causes response sizes to depend on both attacker-supplied mail and other mail within the same mailbox. An attacker capable of sending mail to a user and observing the sizes of that user's IMAP traffic can confirm if the body of a small message matches a guessed text. This can disclose whether a secret-like message body matches a candidate text.
Recommendations
Update to version 2.4.5-1.1.
Disable IMAP compression.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovecot