CVE-2019-19722

In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-12-13 17:15

Updated : 2024-02-04 20:39


NVD link : CVE-2019-19722

Mitre link : CVE-2019-19722

CVE.ORG link : CVE-2019-19722


JSON object : View

Products Affected

dovecot

  • dovecot

fedoraproject

  • fedora
CWE
CWE-476

NULL Pointer Dereference