Displaying 3 results from an estimated 3 matches for "rumata888".
2020 Sep 10
0
Bug in sieve script compilation
Hi, this is Rumata888 from hackerone. This is the other bug I found in
sievec.
If you try to compile the following script, it will result in a panic. The
reason is: export expects its arguments to be either strings or lists of
strings. When we issue an export command with a number immediately
followed by an export comm...
2021 Jan 04
0
CVE-2020-25275: MIME parsing crashes with particular messages
...eport confidence: Confirmed
Solution status: Fixed by Vendor
Fixed version: 2.3.13
Vendor notification: 2020-09-10
Solution date: 2020-09-14
Public disclosure: 2021-01-04
CVE reference: CVE-2020-25275
CVSS: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Researcher credit: Innokentii Sennovskiy (Rumata888) from BI.ZONE
Vulnerability Details:
Mail delivery / parsing crashed when the 10 000th MIME part was
message/rfc822 (or if parent was multipart/digest). This happened
due to earlier MIME parsing changes for CVE-2020-12100.
Risk:
Malicious sender can crash dovecot repeatedly by sending / uploadi...
2021 Jan 04
0
CVE-2020-25275: MIME parsing crashes with particular messages
...eport confidence: Confirmed
Solution status: Fixed by Vendor
Fixed version: 2.3.13
Vendor notification: 2020-09-10
Solution date: 2020-09-14
Public disclosure: 2021-01-04
CVE reference: CVE-2020-25275
CVSS: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Researcher credit: Innokentii Sennovskiy (Rumata888) from BI.ZONE
Vulnerability Details:
Mail delivery / parsing crashed when the 10 000th MIME part was
message/rfc822 (or if parent was multipart/digest). This happened
due to earlier MIME parsing changes for CVE-2020-12100.
Risk:
Malicious sender can crash dovecot repeatedly by sending / uploadi...