CVE-2020-10967
In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.
- Dovecot
- < 2.3.10.1
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 8.2% (95th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2020-05-18
CVE-2020-10967 at NVD
2 known exploits for CVE-2020-10967
Proof-of-concept code and exploit modules indexed by Sploitus