CVE-2008-4907
Last modified
CVE-2008-4907 is a vulnerability of currently unknown severity. The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug.". EPSS estimates a 6.20% chance of exploitation in the next 30 days.
Description
The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dovecot | Dovecot | 1.1.4 |
| Dovecot | Dovecot | 1.1.5 |
References
- http://secunia.com/advisories/32479Patch, Vendor Advisory
- http://secunia.com/advisories/32479Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4907?
How severe is CVE-2008-4907?
How do I fix CVE-2008-4907?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4901SQL injection vulnerability in admin/admin.php in Article Pu…
- CVE-2008-4902SQL injection vulnerability in contact_author.php in Article…
- CVE-2008-4903Cross-site scripting (XSS) vulnerability in the leave commen…
- CVE-2008-4904SQL injection vulnerability in the "Manage pages" feature (a…
- CVE-2008-4905Typo 5.1.3 and earlier uses a hard-coded salt for calculatin…7.5
- CVE-2008-4906SQL injection vulnerability in lyrics_song.php in the Lyrics…
- CVE-2008-4908maps/Info/combine.pl in CrossFire crossfire-maps 1.11.0 allo…
- CVE-2008-4909Cross-site request forgery (CSRF) vulnerability in CompactCM…
- CVE-2008-4910The BasicService in Sun Java Web Start allows remote attacke…
- CVE-2008-4911PHP remote file inclusion vulnerability in read.php in Chatt…
- CVE-2008-4912SQL injection vulnerability in popup_img.php in the fotogale…
- CVE-2008-4913Directory traversal vulnerability in admin.php in LokiCMS 0.…
Are you affected by CVE-2008-4907?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
