The message parsing feature in Dovecot 1.1.4 and 1.1.5, when...
Vulnerability Description
The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-4907
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.dovecot.org/list/dovecot-news/2008-October/000089.html
- http://secunia.com/advisories/33149
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46227
- http://www.ubuntu.com/usn/usn-666-1
- http://www.securityfocus.com/bid/31997
- http://security.gentoo.org/glsa/glsa-200812-16.xml
- http://secunia.com/advisories/32677
- http://secunia.com/advisories/32479
More from dovecot
View All →Affected Vendor
dovecot
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.