CVE-2020-24386
04.01.2021, 17:15
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).Enginsight
Vendor | Product | Version |
---|---|---|
dovecot | dovecot | 2.2.26 ≤ 𝑥 < 2.3.13 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References