The vendor explicitly identifies these products as affected by this CVE.
- dovecot as a component of Red Hat Enterprise Linux 10
- dovecot-devel as a component of Red Hat Enterprise Linux 10
- dovecot-mysql as a component of Red Hat Enterprise Linux 10
- dovecot-pgsql as a component of Red Hat Enterprise Linux 10
- dovecot-pigeonhole as a component of Red Hat Enterprise Linux 10
- dovecot.src as a component of Red Hat Enterprise Linux 10
- dovecot as a component of Red Hat Enterprise Linux 6
- dovecot-devel as a component of Red Hat Enterprise Linux 6
- dovecot-mysql as a component of Red Hat Enterprise Linux 6
- dovecot-pgsql as a component of Red Hat Enterprise Linux 6
- dovecot-pigeonhole as a component of Red Hat Enterprise Linux 6
- dovecot.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in Dovecot. An authenticated attacker can use a Sieve script with the `editheader` extension to trigger a use-after-free vulnerability in the mail editing code. This can lead to memory corruption, potentially crashing the mail delivery process and allowing for arbitrary code execution in the context of that process.
- Remediation
- To mitigate this vulnerability, disable the Sieve `editheader` extension in the Dovecot configuration. After modifying the configuration, the Dovecot service must be restarted for the changes to take effect. Disabling this extension will remove its associated functionality.
