PT-2026-83070 · Dovecot · Dovecot
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
dovecot versions prior to 2.4.5-1.1
Description
A host configured as a trusted proxy can send forwarding information containing a NUL byte. This causes the login process to crash during the subsequent login attempt, leading to process termination and potential denial of service for login functionality. This issue only affects deployments where trusted proxies are configured.
Recommendations
Update to version 2.4.5-1.1.
Restrict the list of trusted proxy networks to hosts that are fully under your control.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovecot