CVE-2020-10957
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.
- Dovecot
- < 2.3.10.1
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 7.2% (94th percentile)
- Weakness
- CWE-476
- NVD status
- Modified
- Published
- 2020-05-18
CVE-2020-10957 at NVD
2 known exploits for CVE-2020-10957
Proof-of-concept code and exploit modules indexed by Sploitus