ZeroHour

CVE-2019-11500

PoC
CVSS 3.0
9.8 critical
EPSS
63%p99
Published
()
Modified
Description

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

Vendors
dovecotdebianfedoraproject
Products
dovecot, pigeonhole, debian linux, fedora
Weakness
CWE-787
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.