CVE-2006-5973

UnknownEPSS 2.65%

Last modified

CVE-2006-5973 is a vulnerability of currently unknown severity. Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.. EPSS estimates a 2.65% chance of exploitation in the next 30 days.

Description

Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.

Metrics

EPSS Probability
2.65%

83.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Timo SirainenDovecot1.0
Timo SirainenDovecot1.0.alpha1
Timo SirainenDovecot1.0.alpha2
Timo SirainenDovecot1.0.alpha3
Timo SirainenDovecot1.0.alpha4
Timo SirainenDovecot1.0.alpha5
Timo SirainenDovecot1.0.beta1
Timo SirainenDovecot1.0.beta2
Timo SirainenDovecot1.0.beta3
Timo SirainenDovecot1.0.beta4
Timo SirainenDovecot1.0.beta5
Timo SirainenDovecot1.0.beta6
Timo SirainenDovecot1.0.beta7
Timo SirainenDovecot1.0.beta8
Timo SirainenDovecot1.0.beta9
Timo SirainenDovecot1.0.rc1
Timo SirainenDovecot1.0.rc2
Timo SirainenDovecot1.0.rc3
Timo SirainenDovecot1.0.rc4
Timo SirainenDovecot1.0.rc5
Timo SirainenDovecot1.0.rc6
Timo SirainenDovecot1.0.rc7
Timo SirainenDovecot1.0.rc8
Timo SirainenDovecot1.0.rc9
Timo SirainenDovecot1.0.rc10
Timo SirainenDovecot1.0.rc11
Timo SirainenDovecot1.0.rc12
Timo SirainenDovecot1.0.rc13
Timo SirainenDovecot1.0.rc14
Timo SirainenDovecot1.0.test53
Timo SirainenDovecot1.0.test54
Timo SirainenDovecot1.0.test55
Timo SirainenDovecot1.0.test56
Timo SirainenDovecot1.0.test57
Timo SirainenDovecot1.0.test58
Timo SirainenDovecot1.0.test59
Timo SirainenDovecot1.0.test60
Timo SirainenDovecot1.0.test61
Timo SirainenDovecot1.0.test62
Timo SirainenDovecot1.0.test63
Timo SirainenDovecot1.0.test64
Timo SirainenDovecot1.0.test65
Timo SirainenDovecot1.0.test66
Timo SirainenDovecot1.0.test67
Timo SirainenDovecot1.0.test68
Timo SirainenDovecot1.0.test69
Timo SirainenDovecot1.0.test70
Timo SirainenDovecot1.0.test71
Timo SirainenDovecot1.0.test72
Timo SirainenDovecot1.0.test73

Showing 50 of 57 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-5973?
Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
How severe is CVE-2006-5973?
Severity scoring for CVE-2006-5973 is pending analysis. The EPSS model estimates a 2.65% probability of exploitation in the next 30 days.
How do I fix CVE-2006-5973?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-5973?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST