CVE-2021-33515

Name
CVE-2021-33515
Description
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://dovecot.org/security
CONFIRM https://www.openwall.com/lists/oss-security/2021/06/28/2
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TK424DWFO2TKJYXZ2H3XL633TYJL4GQN/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JB2VTJ3G2ILYWH5Y2FTY2PUHT2MD6VMI/
Third Party Advisory https://security.gentoo.org/glsa/202107-41

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* dovecot >= None < 2.3.15
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* dovecot >= None < 2.3.14.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dovecot 3.14-main 2.3.15-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
dovecot 3.13-main 2.3.15-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
dovecot 3.12-main 2.3.15-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
dovecot 3.11-main 2.3.15-r0 Natanael Copa <ncopa@alpinelinux.org> fixed