CVE-2020-28200 PUBLISHED

The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.

EPSS 1.24% · 79.2th percentile

Risk Scores

EPSS Score
1.24%
79.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSdovecot1:2.2.9-1ubuntu2.3, 1:2.2.9-1ubuntu2.4, 1:2.2.9-1ubuntu2.5
Ubuntu:16.04:LTSdovecot1:2.2.22-1ubuntu2.11, 1:2.2.22-1ubuntu2.12, 1:2.2.22-1ubuntu2.13
Ubuntu:20.04:LTSdovecot0, 1:2.3.4.1-5ubuntu3, 1:2.3.7.2-1ubuntu1
Ubuntu:18.04:LTSdovecot1:2.2.33.2-1ubuntu4.7, 0, 1:2.2.33.2-1ubuntu4.8

Timeline

References

Open in Interactive Console →