search for: innokentii

Displaying 4 results from an estimated 4 matches for "innokentii".

Did you mean: innocenti
2021 Jan 04
0
CVE-2020-25275: MIME parsing crashes with particular messages
...nent: lda, lmtp, imap Report confidence: Confirmed Solution status: Fixed by Vendor Fixed version: 2.3.13 Vendor notification: 2020-09-10 Solution date: 2020-09-14 Public disclosure: 2021-01-04 CVE reference: CVE-2020-25275 CVSS: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) Researcher credit: Innokentii Sennovskiy (Rumata888) from BI.ZONE Vulnerability Details: Mail delivery / parsing crashed when the 10 000th MIME part was message/rfc822 (or if parent was multipart/digest). This happened due to earlier MIME parsing changes for CVE-2020-12100. Risk: Malicious sender can crash dovecot repeatedl...
2021 Jun 21
0
CVE-2020-28200: Sieve excessive resource usage
...component: lmtp, lda Report confidence: Confirmed Solution status: Fixed by Vendor Fixed version: 2.3.15 Vendor notification: 2020-09-23 Solution date: 2020-12-07 Public disclosure: 2021-06-21 CVE reference: CVE-2020-28200 CVSS: 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L) Researcher credit: Innokentii Sennovskii from BI.ZONE Vulnerability Details: Sieve interpreter is not protected against abusive scripts that claim excessive resource usage. Especially scripts using massive amounts of regexps. Risk: Attacker can DoS the mail delivery system by using excessive amount of CPU and/or reaching the...
2021 Jan 04
0
CVE-2020-25275: MIME parsing crashes with particular messages
...nent: lda, lmtp, imap Report confidence: Confirmed Solution status: Fixed by Vendor Fixed version: 2.3.13 Vendor notification: 2020-09-10 Solution date: 2020-09-14 Public disclosure: 2021-01-04 CVE reference: CVE-2020-25275 CVSS: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) Researcher credit: Innokentii Sennovskiy (Rumata888) from BI.ZONE Vulnerability Details: Mail delivery / parsing crashed when the 10 000th MIME part was message/rfc822 (or if parent was multipart/digest). This happened due to earlier MIME parsing changes for CVE-2020-12100. Risk: Malicious sender can crash dovecot repeatedl...
2021 Jun 21
0
CVE-2020-28200: Sieve excessive resource usage
...component: lmtp, lda Report confidence: Confirmed Solution status: Fixed by Vendor Fixed version: 2.3.15 Vendor notification: 2020-09-23 Solution date: 2020-12-07 Public disclosure: 2021-06-21 CVE reference: CVE-2020-28200 CVSS: 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L) Researcher credit: Innokentii Sennovskii from BI.ZONE Vulnerability Details: Sieve interpreter is not protected against abusive scripts that claim excessive resource usage. Especially scripts using massive amounts of regexps. Risk: Attacker can DoS the mail delivery system by using excessive amount of CPU and/or reaching the...