PT-2026-83068 · Dovecot · Dovecot
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
dovecot versions prior to 2.4.5-1.1
Description
An attacker with valid credentials can send an invalid IMAP URLFETCH command, causing the system to include uninitialized memory in the error response returned to the client. This can lead to the disclosure of process memory contents, which may contain sensitive data.
Recommendations
Update to version 2.4.5-1.1.
Disable the IMAP URLAUTH functionality.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovecot