CVE-2020-25275
Description
Dovecot lda, lmtp, and imap crash when parsing crafted email with >10,000 MIME parts, affecting versions 2.3.11-2.3.11.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dovecot lda, lmtp, and imap crash when parsing crafted email with >10,000 MIME parts, affecting versions 2.3.11-2.3.11.3.
Vulnerability
Dovecot lda, lmtp, and imap components suffer from improper input validation (CWE-20) when processing email messages with a large number of MIME parts. Specifically, the crash occurs when the 10,000th MIME part is of type message/rfc822 or if its parent is multipart/digest. This issue was introduced by earlier MIME parsing changes for CVE-2020-12100. Versions 2.3.11 through 2.3.11.3 are affected [1][2].
Exploitation
An attacker can send or upload a crafted email message containing more than 10,000 MIME parts to any Dovecot server running the vulnerable version. The attacker requires no authentication or user interaction, as the crash occurs during message delivery or parsing by lda, lmtp, or imap [1][2].
Impact
Successful exploitation causes a crash (denial of service) of the Dovecot process handling the message. The CVSS score is 5.3 (medium) with impact only on availability (C:N/I:N/A:L). Repeated crashes can disrupt email services [1].
Mitigation
The vulnerability is fixed in Dovecot version 2.3.13, released on 2020-09-14. Users should upgrade to 2.3.13 or later. A workaround is to filter such messages at the MTA (Mail Transfer Agent), which typically drops emails with excessively many MIME parts [1][2]. The CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
15- Dovecot/Dovecotdescription
- Range: <2.3.13
- osv-coords13 versionspkg:rpm/almalinux/dovecotpkg:rpm/almalinux/dovecot-develpkg:rpm/almalinux/dovecot-mysqlpkg:rpm/almalinux/dovecot-pgsqlpkg:rpm/almalinux/dovecot-pigeonholepkg:rpm/opensuse/dovecot23&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/dovecot23&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015
< 1:2.3.8-9.el8+ 12 more
- (no CPE)range: < 1:2.3.8-9.el8
- (no CPE)range: < 1:2.3.8-9.el8
- (no CPE)range: < 1:2.3.8-9.el8
- (no CPE)range: < 1:2.3.8-9.el8
- (no CPE)range: < 1:2.3.8-9.el8
- (no CPE)range: < 2.3.11.3-lp151.2.15.1
- (no CPE)range: < 2.3.11.3-lp152.2.6.1
- (no CPE)range: < 2.3.11.3-4.32.1
- (no CPE)range: < 2.3.11.3-4.32.1
- (no CPE)range: < 2.3.11.3-21.1
- (no CPE)range: < 2.3.11.3-17.5.1
- (no CPE)range: < 2.3.11.3-4.32.1
- (no CPE)range: < 2.3.11.3-4.32.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
8- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXDKFLOCUP7I4ELGQ2F4P5TGC6NXMYV7/mitrevendor-advisoryx_refsource_FEDORA
- security.gentoo.org/glsa/202101-01mitrevendor-advisoryx_refsource_GENTOO
- www.debian.org/security/2021/dsa-4825mitrevendor-advisoryx_refsource_DEBIAN
- packetstormsecurity.com/files/160841/Dovecot-2.3.11.3-Denial-Of-Service.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2021/Jan/18mitremailing-listx_refsource_FULLDISC
- www.openwall.com/lists/oss-security/2021/01/04/3mitrex_refsource_CONFIRM
- dovecot.org/pipermail/dovecot-news/2021-January/000451.htmlmitrex_refsource_CONFIRM
- dovecot.org/securitymitrex_refsource_MISC
News mentions
0No linked articles in our index yet.