<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:06:23 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:6529 — Moderate: dovecot security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:6529</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: dovecot, AlmaLinux:9: dovecot-devel, AlmaLinux:9: dovecot-mysql, AlmaLinux:9: dovecot-pgsql, AlmaLinux:9: dovecot-pigeonhole&lt;/p&gt;
&lt;p&gt;Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dovecot: using a large number of address headers may trigger a denial of service (CVE-2024-23184)
* dovecot: very large headers can cause resource exhaustion when parsing message (CVE-2024-23185)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: dovecot, AlmaLinux:9: dovecot-devel, AlmaLinux:9: dovecot-mysql, AlmaLinux:9: dovecot-pgsql, AlmaLinux:9: dovecot-pigeonhole&lt;/p&gt;
&lt;p&gt;Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dovecot: using a large number of address headers may trigger a denial of service (CVE-2024-23184)
* dovecot: very large headers can cause resource exhaustion when parsing message (CVE-2024-23185)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:6529</guid>
    </item>
    <item>
      <title>bdu:2024-06559</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06559</link>
      <description>bdu:2024-06559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06559</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0710 — De multiples vulnérabilités ont été découvertes dans les produits Dovecot. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0710</link>
      <description>certfr-2024-avi-0710</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0710</guid>
    </item>
    <item>
      <title>EUVD-2026-258879</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258879</link>
      <description>EUVD-2026-258879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258879</guid>
    </item>
    <item>
      <title>fkie_cve-2024-23184</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23184</link>
      <description>&lt;p&gt;Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-23184</guid>
    </item>
    <item>
      <title>GHSA-5f48-j349-fj3m</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5f48-j349-fj3m</link>
      <description>&lt;p&gt;Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5f48-j349-fj3m</guid>
    </item>
    <item>
      <title>gsd-2024-23184</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-23184</link>
      <description>gsd-2024-23184</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-23184</guid>
    </item>
    <item>
      <title>OESA-2024-2009 — dovecot security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: dovecot, openEuler:24.03-LTS: dovecot, openEuler:22.03-LTS-SP4: dovecot, openEuler:22.03-LTS-SP3: dovecot, openEuler:20.03-LTS-SP4: dovecot&lt;/p&gt;
&lt;p&gt;Dovecot is an IMAP server for Linux/UNIX-like systemsa wrapper package that will just handle common things for all versioned dovecot packages.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;(CVE-2024-23184)&lt;/p&gt;
&lt;p&gt;(CVE-2024-23185)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: dovecot, openEuler:24.03-LTS: dovecot, openEuler:22.03-LTS-SP4: dovecot, openEuler:22.03-LTS-SP3: dovecot, openEuler:20.03-LTS-SP4: dovecot&lt;/p&gt;
&lt;p&gt;Dovecot is an IMAP server for Linux/UNIX-like systemsa wrapper package that will just handle common things for all versioned dovecot packages.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;(CVE-2024-23184)&lt;/p&gt;
&lt;p&gt;(CVE-2024-23185)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2009</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14274-1 — dovecot23-2.3.21.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14274-1</link>
      <description>&lt;p&gt;dovecot23-2.3.21.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dovecot23-2.3.21.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14274-1</guid>
    </item>
    <item>
      <title>OXDC-ADV-2024-0002 — OX Dovecot Pro Security Advisory OXDC-ADV-2024-0002</title>
      <link>https://cve.radiocsirt.org/vuln/oxdc-adv-2024-0002</link>
      <description>OXDC-ADV-2024-0002</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oxdc-adv-2024-0002</guid>
    </item>
    <item>
      <title>RHSA-2024:6465 — Red Hat Security Advisory: dovecot security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6465</link>
      <description>&lt;p&gt;dovecot: using a large number of address headers may trigger a denial of service dovecot: very large headers can cause resource exhaustion when parsing message&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dovecot: using a large number of address headers may trigger a denial of service dovecot: very large headers can cause resource exhaustion when parsing message&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6465</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-23184</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23184</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dovecot, Ubuntu:24.04:LTS: dovecot&lt;/p&gt;
&lt;p&gt;Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dovecot, Ubuntu:24.04:LTS: dovecot&lt;/p&gt;
&lt;p&gt;Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23184</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1867 — Dovecot: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1867</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Dovecot ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Dovecot ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1867</guid>
    </item>
  </channel>
</rss>
