Lucene search

K
osvGoogleOSV:CVE-2019-11500
HistoryAug 29, 2019 - 2:15 p.m.

CVE-2019-11500

2019-08-2914:15:11
Google
osv.dev
7

9.8 High

AI Score

Confidence

High

0.614 Medium

EPSS

Percentile

97.8%

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because ‘\0’ characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

References