CVE-2020-10967

MEDIUM5.3EPSS 3.4%
Published: 5/18/2020Modified: 12/3/2025
Also known as:ALPINE-CVE-2020-10967DEBIAN-CVE-2020-10967

Description

In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References (2)