CVE-2006-5973 - CVE House
Back to Database
Status published Medium CVE-2006-5973

Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly...

Vulnerability Description

Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-5973

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

timo sirainen

View all reports →

Affected Software

dovecot
Vulnerable Versions:
1.0, 1.0.alpha1, 1.0.alpha2, 1.0.alpha3, 1.0.alpha4, 1.0.alpha5, 1.0.beta1, 1.0.beta2, 1.0.beta3, 1.0.beta4, 1.0.beta5, 1.0.beta6, 1.0.beta7, 1.0.beta8, 1.0.beta9, 1.0.rc1, 1.0.rc2, 1.0.rc3, 1.0.rc4, 1.0.rc5, 1.0.rc6, 1.0.rc7, 1.0.rc8, 1.0.rc9, 1.0.rc10, 1.0.rc11, 1.0.rc12, 1.0.rc13, 1.0.rc14, 1.0.test53, 1.0.test54, 1.0.test55, 1.0.test56, 1.0.test57, 1.0.test58, 1.0.test59, 1.0.test60, 1.0.test61, 1.0.test62, 1.0.test63, 1.0.test64, 1.0.test65, 1.0.test66, 1.0.test67, 1.0.test68, 1.0.test69, 1.0.test70, 1.0.test71, 1.0.test72, 1.0.test73, 1.0.test74, 1.0.test75, 1.0.test76, 1.0.test77, 1.0.test78, 1.0.test79, 1.0.test80

Timeline

Official Publish: November 20th, 2006
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.