CVE-2020-7046 describes a vulnerability in Dovecot versions 2.3.9 before 2.3.9.3, where mishandling of truncated UTF-8 data in command parameters can lead to an unauthenticated infinite loop in the submission-login and lmtp components. This high-severity vulnerability (CVSS 7.5) is easily exploitable over the network with low attack complexity and no user interaction, potentially causing a denial of service. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.9, < 2.3.9.3CPE matchmatch criteria | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
dovecot: Attacker can cause submission-login and lmtp processes to be exhausted leading to DoS
Feb 12, 2020Truncated UTF-8 can be used to DoS submission-login and lmtp processes
Feb 12, 2020Truncated UTF-8 can be used to DoS submission-login and lmtp processes
Feb 12, 2020Truncated UTF-8 can be used to DoS submission-login and lmtp processes
Feb 12, 2020Truncated UTF-8 can be used to DoS submission-login and lmtp processes
Feb 12, 2020CVE-2020-7046: Truncated UTF-8 can be used to DoS submission-login and lmtp processes
Feb 12, 2020Truncated UTF-8 can be used to DoS submission-login and lmtp processes
Feb 12, 2020CVE-2020-7046: Truncated UTF-8 can be used to DoS submission-login and lmtp processes
Feb 12, 2020