漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Dovecot 安全漏洞
Vulnerability Description
Dovecot是一款开源的基于类Linux/UNIX系统的IMAP和POP3邮件服务器。 Dovecot 2.2.26版本至2.2.28版本中存在远程拒绝服务漏洞。远程攻击者可利用该漏洞造成进程崩溃或占用过多CPU资源,导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A