Back to search
CVE-2019-19722
Published: Dec 13, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://dovecot.org/list/dovecot-news/2019-December/000428.html
x_refsource_CONFIRM
https://dovecot.org/security.html
x_refsource_CONFIRM
http://www.openwall.com/lists/oss-security/2019/12/13/3
x_refsource_CONFIRM
https://dovecot.org/pipermail/dovecot-news/2019-December/000428.html
x_refsource_CONFIRM
FEDORA-2019-5898f4f935
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-72e5ac943a
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now