CVE-2020-10967 PUBLISHED

In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.

EPSS 5.03% · 89.7th percentile

Risk Scores

EPSS Score
5.03%
89.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSdovecot0, 1:2.3.4.1-5ubuntu3, 1:2.3.7.2-1ubuntu1

Timeline

References

Open in Interactive Console →