NULL pointer dereference in Dovecot - CVE-2019-11494

 

NULL pointer dereference in Dovecot - CVE-2019-11494

Published: May 6, 2019


Vulnerability identifier: #VU18399
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11494
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error within Submission-login when processing authentication. A remote attacker can unexpectedly abort the authentication process by disconnecting from the server during authentication and cause the software to crash.


Affected software

Dovecot
Arch Linux
Opensuse
Fedora
dovecot (Alpine package)
dovecot (Ubuntu package)
dovecot
Dell PowerProtect Cyber Recovery

How to mitigate CVE-2019-11494

Install updates from vendor's website.

Dovecot - update to 2.3.6
dovecot (Alpine package) - update to 2.3.6-r0
dovecot (Ubuntu package) - addressed in versions 1:2.3.2.1-1ubuntu3.4, 1:2.3.4.1-1ubuntu2.2
dovecot - addressed in versions 2.3.6-3.fc29, 2.3.6-3.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8

External References

Related Security Bulletins