CVE-2024-25584

Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails. Upgrade to latest released version. No publicly available exploits are known.
Configurations

No configuration.

History

06 Sep 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-06 15:15

Updated : 2024-09-06 16:46


NVD link : CVE-2024-25584

Mitre link : CVE-2024-25584

CVE.ORG link : CVE-2024-25584


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity