CVE-2019-11500
dovecot - security update
9.8
CRITICAL
CVSS 3.1
EPSS 62.6%
Description
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
How to fix CVE-2019-11500
To remediate CVE-2019-11500, upgrade the affected package to a fixed version below.
- Alpine/dovecot—upgrade to 2.3.7.2-r0 or later
Is CVE-2019-11500 being exploited?
Likely — EPSS is 62.6%, placing CVE-2019-11500 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- >= 2.3.0, < 2.3.7.2-r0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |