Critical vulnerability in the Dovecot IMAP server
In the corrective releases of the POP3/IMAP4 server Dovecot 2.3.7.2 and 2.2.36.4, as well as in the add-on Pigeonhole 0.5.7.2 and 0.4.24.2, a critical vulnerability (CVE-2019-11500) was addressed that allows for data to be written outside the allocated buffer by sending specially crafted requests via the IMAP or ManageSieve protocols. This issue can be exploited even before authentication is completed. A working exploit has yet to be prepared, but […]
