Total vulnerabilities in the database
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
Software | From | Fixed in |
---|---|---|
dovecot / dovecot | 2.2.26 | 2.3.13 |
debian / debian_linux | 10.0 | 10.0.x |
fedoraproject / fedora | 32 | 32.x |