CVE-2020-10958
In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.
- Dovecot
- < 2.3.10.1
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 6.1% (93th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2020-05-18
CVE-2020-10958 at NVD
2 known exploits for CVE-2020-10958
Proof-of-concept code and exploit modules indexed by Sploitus