Unrated severityNVD Advisory· Published May 24, 2011· Updated Apr 29, 2026
CVE-2011-1929
CVE-2011-1929
Description
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
Affected products
31cpe:2.3:a:dovecot:dovecot:1.2.0:*:*:*:*:*:*:*+ 30 more
- cpe:2.3:a:dovecot:dovecot:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.12:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.13:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.14:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.15:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.16:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:1.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:dovecot:dovecot:2.0:beta1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
25- dovecot.org/pipermail/dovecot/2011-May/059085.htmlnvdPatch
- dovecot.org/pipermail/dovecot/2011-May/059086.htmlnvdPatch
- hg.dovecot.org/dovecot-1.1/rev/3698dfe0f21cnvdPatch
- openwall.com/lists/oss-security/2011/05/18/4nvdPatch
- openwall.com/lists/oss-security/2011/05/19/3nvdPatch
- openwall.com/lists/oss-security/2011/05/19/6nvdPatch
- bugzilla.redhat.com/show_bug.cginvdPatch
- lists.fedoraproject.org/pipermail/package-announce/2011-June/061384.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-May/060815.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-May/060825.htmlnvd
- osvdb.org/72495nvd
- secunia.com/advisories/44683nvd
- secunia.com/advisories/44712nvd
- secunia.com/advisories/44756nvd
- secunia.com/advisories/44771nvd
- secunia.com/advisories/44827nvd
- www.debian.org/security/2011/dsa-2252nvd
- www.dovecot.org/doc/NEWS-1.2nvd
- www.dovecot.org/doc/NEWS-2.0nvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2011-1187.htmlnvd
- www.securityfocus.com/bid/47930nvd
- www.ubuntu.com/usn/USN-1143-1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/67589nvd
- hermes.opensuse.org/messages/8581790nvd
News mentions
0No linked articles in our index yet.