یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
متوسط CVSS 7.5 EPSS 0.8% اولویت 38/100

CVE-2024-23184— CVE-2024-23184: داشتن تعداد زیادی هدر آدرس (از، به، رونوشت، رونوشت مخفی و غیره) به شدت CPU را درگیر می‌کند - dovecot - dovecot.org

Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long header line, or a single header split into multiple lines. This bug exists in all Dovecot versions. Incoming mails typically have some size limits set by MTA, so even largest possible header size may still fit into Dovecot's vsz_limit. So attackers probably can't DoS a victim user this way. A user could APPEND larger mails though, allowing them to DoS themselves (although maybe cause some memory issues for the…

انتشار: 2024-01-30 00:00 آخرین مشاهده داده: 2026-08-28 15:25 1 منبع · 1 رسمیاعتماد متوسط · 43/100
اولویت VulnWatch 38/100 ترکیب سیگنال‌های ریسک موجود
CVSS / EPSS 7.5 / 0.8% شدت فنی / احتمال بهره‌برداری
کیفیت داده 49/100 کیفیت محدود · اعتماد متوسط
تازگی داده قدیمی قدیمی‌تر از ۳۰ روز · 1 منبع
راهنمای اقدام

الان چه کاری باید انجام شود؟

پایش و ارزیابی
EPSS 0.8%سیگنال EPSS پایین‌تر است؛ سایر شاخص‌ها را نیز در تصمیم لحاظ کنید.
کیفیت داده 49/100کیفیت محدود · 1 منبع؛ پیش از تغییر Production منبع اصلی را بررسی کنید.
راهکارراهکار در این صفحه ثبت شده است؛ بخش راهکار پیشنهادی را بررسی کنید.
رفتن به راهکار این راهنمای اقدام، RiskScorer را تغییر نمی‌دهد و جایگزین ارزیابی محیط شما نیست.
اولویت عملیاتی 2.5

چرا این مورد باید بررسی شود؟

این امتیاز مستقل از RiskScorer است و برای مرتب‌سازی اقدام‌های عملیاتی استفاده می‌شود.

Priority24
راهکار اجرایی موجود
01

خلاصه آسیب‌پذیری

Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long header line, or a single header split into multiple lines. This bug exists in all Dovecot versions. Incoming mails typically have some size limits set by MTA, so even largest possible header size may still fit into Dovecot's vsz_limit. So attackers probably can't DoS a victim user this way. A user could APPEND larger mails though, allowing them to DoS themselves (although maybe cause some memory issues for the…
02

توضیحات کامل

newer CVE-2024-23184: Having a large... Dovecot CVE-2024-23185: Very large headers can cause resource exhaustion when parsing message older Pigeonhole v0.5.21.1 released Aki Tuomi 14 Aug 2024 14 Aug '24 2:26 p.m. Affected product: Dovecot IMAP Server Internal reference: DOV-6601 Vulnerability type: CWE-770 (Allocation of Resources Without Limits or Throttling) Vulnerable version: 2.2, 2.3 Vulnerable component: lib-mail Report confidence: Confirmed Solution status: Fixed in 2.3.21.1 Researcher credits: Vendor internal discovery Vendor notification: 2024-01-31 CVE reference: CVE-2024-23185 CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Vulnerability Details: Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long header line, or a single header split into multiple lines. This bug exists in all Dovecot versions. Incoming mails typically have some size limits set by MTA, so even largest possible header size may still fit into Dovecot's vsz_limit. So attackers probably can't DoS a victim user this way. A user could APPEND larger mails though, allowing them to DoS themselves (although maybe cause some memory issues for the backend in general). Workaround: One can implement restrictions on headers on MTA component preceding Dovecot. Fix: Install non-vulnerable version of Dovecot. Patch can be found at https://github.com/dovecot/core/compare/f020e13%5E...ce88c33.patch Attachments: signature.asc (application/pgp-signature — 485 bytes) 0 0 Reply Sign in to reply online Use email software Show replies by date Visit here for a non-javascript version of this page. 744 Age (days ago) 744 Last active (days ago) List overview 0 comments 1 participants Add to favorites Remove from favorites tags participants (1) Aki Tuomi
03

اثر و پیامد امنیتی

Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long header line, or a single header split into multiple lines. This bug exists in all Dovecot versions. Incoming mails typically have some size limits set by MTA, so even largest possible header size may still fit into Dovecot's vsz_limit. So attackers probably can't DoS a victim user this way. A user could APPEND larger mails though, allowing them to DoS themselves (although maybe cause some memory issues for the backend in general).
✓

راهکار پیشنهادی برای رفع

اقدام پیشنهادی
Install non-vulnerable version of Dovecot. Patch can be found at https://github.com/dovecot/core/compare/f020e13%5E...ce88c33.patch
↻

راهکار موقت

One can implement restrictions on address headers on MTA component preceding Dovecot.
↺

تاریخچه تغییرات معنادار

فقط تغییرات امنیتی مهم مثل KEV، افزایش شدت/CVSS/EPSS، نسخه‌های درگیر و راهکار ثبت می‌شوند.
تاریخچه معنادار از زمان فعال‌شدن موتور 2.5 ساخته می‌شود.
◎

اعتماد، تازگی و پوشش داده

این شاخص عملیاتی از پوشش منابع، کامل‌بودن رکورد، تازگی داده و اختلاف بین منابع ساخته می‌شود و تضمین صحت نیست.
43/100
اعتماد متوسط اعتماد داده 49/100 کیفیت محدود داده قدیمی وضعیت تازگی قدیمی‌تر از ۳۰ روز تازگی مشاهده 100/100 کامل‌بودن · کامل 52/100 پوشش منابع 1 منبع مرتبط 1 رسمی · 1 سطح ۱ 3 اختلاف بین منابع 0 خلأ کیفیت
اختلاف بین منابع دیده شد

اختلاف‌ها مخفی نمی‌شوند و در شاخص اعتماد نیز اثر کاهشی دارند. پیش از تصمیم عملیاتی، مقدار هر منبع را بررسی کنید.

CVSS
5.07.5
شدت
mediumlow
تاریخ انتشار
2024-01-302024-01-31
Dovecot Security رسمی
CVSS
5
شدت
medium
محصول
Dovecot / Dovecot
نسخه درگیر
—
نسخه اصلاح‌شده
2.3.21.1
تاریخ انتشار منبع
2024-01-30
Dovecot Security رسمی
CVSS
7.5
شدت
low
محصول
Dovecot / Dovecot
نسخه درگیر
—
نسخه اصلاح‌شده
2.3.21.1
تاریخ انتشار منبع
2024-01-31
⌁

منبع هر داده

برای فیلدهای اصلی می‌توانید ببینید هر مقدار از کدام منبع ثبت شده است. اختلاف بین منابع پنهان نمی‌شود.
CVSS 2 منبع
Dovecot Securityرسمی
5
منبع ↗
Dovecot Securityرسمی
7.5
منبع ↗
توضیحات 2 منبع
Dovecot Securityرسمی
newer Dovecot refuses to install/run on... CVE-2024-23184: Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive older Dovecot CVE-2024-23185: Very large... Aki Tuomi 14 Aug 2024 14 Aug '24 2:26 p.m. Affected product: Dovecot IMAP Server Internal reference: DOV-6464 Vulnerability type: CWE-770 (Allocation of Resources Without Limits or Thro...
منبع ↗
Dovecot Securityرسمی
newer CVE-2024-23184: Having a large... Dovecot CVE-2024-23185: Very large headers can cause resource exhaustion when parsing message older Pigeonhole v0.5.21.1 released Aki Tuomi 14 Aug 2024 14 Aug '24 2:26 p.m. Affected product: Dovecot IMAP Server Internal reference: DOV-6601 Vulnerability type: CWE-770 (Allocation of Resources Without Limits or Throttling) Vulnerable version: 2.2, 2...
منبع ↗
نسخه‌های اصلاح‌شده 2 منبع
Dovecot Securityرسمی
2.3.21.1
منبع ↗
Dovecot Securityرسمی
2.3.21.1
منبع ↗
اثر 2 منبع
Dovecot Securityرسمی
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. The main problem is that each header line's addres...
منبع ↗
Dovecot Securityرسمی
Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long...
منبع ↗
راهکار 2 منبع
Dovecot Securityرسمی
Install non-vulnerable version of Dovecot. Patch can be found at https://github.com/dovecot/core/compare/8e4c42d%5E...1481c04.patch
منبع ↗
Dovecot Securityرسمی
Install non-vulnerable version of Dovecot. Patch can be found at https://github.com/dovecot/core/compare/f020e13%5E...ce88c33.patch
منبع ↗
شدت 2 منبع
Dovecot Securityرسمی
medium
منبع ↗
Dovecot Securityرسمی
low
منبع ↗
خلاصه 2 منبع
Dovecot Securityرسمی
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. The main problem is that each header line's addres...
منبع ↗
Dovecot Securityرسمی
Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long...
منبع ↗
عنوان 2 منبع
Dovecot Securityرسمی
CVE-2024-23184: Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive - dovecot - dovecot.org
منبع ↗
Dovecot Securityرسمی
Dovecot CVE-2024-23185: Very large headers can cause resource exhaustion when parsing message - dovecot - dovecot.org
منبع ↗
راهکار موقت 2 منبع
Dovecot Securityرسمی
One can implement restrictions on address headers on MTA component preceding Dovecot.
منبع ↗
Dovecot Securityرسمی
One can implement restrictions on headers on MTA component preceding Dovecot.
منبع ↗
↗