NULL pointer dereference in Dovecot - CVE-2019-11494
Published: May 6, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within Submission-login when processing authentication. A remote attacker can unexpectedly abort the authentication process by disconnecting from the server during authentication and cause the software to crash.
Affected software
Arch Linux
Opensuse
Fedora
dovecot (Alpine package)
dovecot (Ubuntu package)
dovecot
Dell PowerProtect Cyber Recovery
How to mitigate CVE-2019-11494
dovecot (Alpine package) - update to 2.3.6-r0
dovecot (Ubuntu package) - addressed in versions 1:2.3.2.1-1ubuntu3.4, 1:2.3.4.1-1ubuntu2.2
dovecot - addressed in versions 2.3.6-3.fc29, 2.3.6-3.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
Related Security Bulletins
- Multiple vulnerabilities in Dovecot
- Arch Linux update for dovecot
- Ubuntu update for Dovecot
- OpenSUSE Linux update for dovecot23
- OpenSUSE Linux update for dovecot23
- NULL pointer dereference in dovecot (Alpine package)
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Fedora 30 update for dovecot
- Fedora 29 update for dovecot