CVE-2008-4907 Information
Feb 14, 2021
cve
Description
The message parsing feature in Dovecot 1.1.4 and 1.1.5 when using the FETCH ENVELOPE command in the IMAP client allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address which triggers an assertion error aka \invalid message address parsing bug.\
Reference
http://secunia.com/advisories/32479 http://secunia.com/advisories/32677 http://secunia.com/advisories/33149 http://security.gentoo.org/glsa/glsa-200812-16.xml http://www.dovecot.org/list/dovecot-news/2008-October/000089.html http://www.securityfocus.com/bid/31997 http://www.ubuntu.com/usn/usn-666-1 https://exchange.xforce.ibmcloud.com/vulnerabilities/46227
Share on: