Information disclosure in Dovecot and OX Dovecot Pro - CVE-2025-59031

 

Information disclosure in Dovecot and OX Dovecot Pro - CVE-2025-59031

Published: April 1, 2026


Vulnerability identifier: #VU124723
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59031
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in decode2text.sh script when parsing OOXML attachments during indexing. A remote attacker can send a specially crafted OOXML document containing symlinks to disclose sensitive information.

The attacker must be able to upload email attachments that are processed by the indexing system.


Affected software

Dovecot
OX Dovecot Pro
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
openEuler
Ubuntu
dovecot22-backend-pgsql-debuginfo
dovecot22-backend-sqlite
dovecot22-devel
dovecot22
dovecot22-debuginfo
dovecot22-backend-pgsql
dovecot22-backend-mysql-debuginfo
dovecot22-backend-sqlite-debuginfo
dovecot22-debugsource
dovecot22-backend-mysql
dovecot-help
dovecot-devel
dovecot-debugsource
dovecot-debuginfo
dovecot
dovecot (Ubuntu package)

How to mitigate CVE-2025-59031

Install security update from vendor's website.

Dovecot - update to 2.4.3
OX Dovecot Pro - addressed in versions 2.3.22.1, 3.1.3
dovecot22-backend-pgsql-debuginfo - update to 2.2.31-19.32.1
dovecot22-backend-sqlite - update to 2.2.31-19.32.1
dovecot22-devel - update to 2.2.31-19.32.1
dovecot22 - update to 2.2.31-19.32.1
dovecot22-debuginfo - update to 2.2.31-19.32.1
dovecot22-backend-pgsql - update to 2.2.31-19.32.1
dovecot22-backend-mysql-debuginfo - update to 2.2.31-19.32.1
dovecot22-backend-sqlite-debuginfo - update to 2.2.31-19.32.1
dovecot22-debugsource - update to 2.2.31-19.32.1
dovecot22-backend-mysql - update to 2.2.31-19.32.1
dovecot-help - update to 2.3.15-7
dovecot-devel - update to 2.3.15-7
dovecot-debugsource - update to 2.3.15-7
dovecot-debuginfo - update to 2.3.15-7
dovecot - update to 2.3.15-7
dovecot (Ubuntu package) - addressed in versions 1:2.3.16+dfsg1-3ubuntu2.7, 1:2.3.16+dfsg1-3ubuntu2.8, 1:2.3.21+dfsg1-2ubuntu6.3, 1:2.3.21+dfsg1-2ubuntu6.4, 1:2.4.1+dfsg1-5ubuntu4.1

External References

Related Security Bulletins