VDB
GCVE-VVD-MAGEIA-2021-557
GCVE-VVD-MAGEIA-2021-557
Advisory Published
Updated dovecot packages fix security vulnerabilities:
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource
Consumption, as demonstrated by a situation with a complex regular
expression for the regex extension (CVE-2020-28200).
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access
to the local filesystem can trick OAuth2 authentication into using an HS256
validation key from an attacker-controlled location. This occurs during use
of local JWT validation with the posix fs driver (CVE-2021-29157).
The submission service in Dovecot before 2.3.15 allows STARTTLS command
injection in lib-smtp. Sensitive information can be redirected to an
attacker-controlled address (CVE-2021-33515).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | dovecot | 0 (affected), 2.3.17.1-1.1.mga8 (unaffected) | — |
Aliases
Transitive aliases
GHSA-f6jc-wwhw-gpq7GHSA-44wx-mcwc-xfg9CVE-2008-2936EUVD-2021-15796EUVD-2011-0437VVD-GENTOO-2011-358375EUVD-2011-1576EUVD-2011-0444GHSA-93q5-9xfx-j4cwGHSA-g8vx-5jmv-rgqxEUVD-2008-2929VVD-GENTOO-2011-365751CVE-2011-0411EUVD-2011-1435GHSA-p5jh-65m7-7pfgGSD-2011-1432GHSA-mqpg-5c3p-cx82GHSA-c4mq-4wp5-9pxqRHSA-2008:0839GHSA-pwmq-cvcm-r5p2CVE-2026-41319GHSA-2gf2-4wwm-4cm6VVD-CERTCC-2011-555316CVE-2011-0418TNCVE-2026-41319CVE-2011-1575GHSA-8739-vxjm-m9p4VVD-CERTCC-2020-938323CVE-2011-1432EUVD-2011-1436EUVD-2026-25388H1-953219RHSA-2011:0422EUVD-2011-1437BDU:2021-03236EUVD-2020-20684GHSA-89g9-v7q6-px25CVE-2008-2937GSD-2011-0418BDU:2021-03234GSD-2011-1430VVD-GENTOO-2008-242638GHSA-9j88-vvj5-vhgrRHSA-2011:0423CVE-2011-1430EUVD-2008-2930OPENSUSE-SU-2024:10318-1BDU:2021-03235GSD-2011-1575VVD-GENTOO-2011-372967GSD-2011-1431VVD-GENTOO-2008-232642ALSA-2022:1950VVD-GENTOO-2011-358085CVE-2011-1431VAR-201103-0090VVD-GENTOO-2021-797349EUVD-2021-20207
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.