Critical severity9.8NVD Advisory· Published Aug 29, 2019· Updated Jun 17, 2026
CVE-2019-11500
CVE-2019-11500
Description
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*range: <2.2.36.4
- (no CPE)range: <2.2.36.4, <2.3.7.2
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- Dovecot/Dovecotdescription
- osv-coords25 versionspkg:rpm/opensuse/dovecot23&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/dovecot23&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/dovecot23&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/dovecot24&distro=openSUSE%20Tumbleweedpkg:rpm/suse/dovecot22&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/dovecot22&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/dovecot22&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/dovecot22&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/dovecot22&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/dovecot22&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1
< 2.3.3-lp150.14.1+ 24 more
- (no CPE)range: < 2.3.3-lp150.14.1
- (no CPE)range: < 2.3.3-lp151.2.6.1
- (no CPE)range: < 2.3.16-1.6
- (no CPE)range: < 2.4.0-1.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.2.31-19.17.1
- (no CPE)range: < 2.3.3-8.1
Patches
Vulnerability mechanics
References
13- dovecot.org/pipermail/dovecot-news/2019-August/000417.htmlnvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2019/08/28/3nvdExploitMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/08/msg00035.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201908-29nvdThird Party Advisory
- www.dovecot.org/security.htmlnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2019-10/msg00024.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-10/msg00026.htmlnvd
- access.redhat.com/errata/RHSA-2019:2822nvd
- access.redhat.com/errata/RHSA-2019:2836nvd
- access.redhat.com/errata/RHSA-2019:2885nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3GYTZLLDNIFWT7D7JSB25ERJNMOR4CQ3/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KVHY3MU2OK2EWZJFGNDSAOMD42L7DFPX/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSJVVVRAE3SITC2ZLGCPMFDN3WVYZBWF/nvd
News mentions
0No linked articles in our index yet.