Total vulnerabilities in the database
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
Software | From | Fixed in |
---|---|---|
dovecot / dovecot | - | 2.3.9.2 |
fedoraproject / fedora | 30 | 30.x |
fedoraproject / fedora | 31 | 31.x |