CVE-2019-11500: Debian Linux

Critical severity, CVSS 9.8. EPSS: 62.3% chance of exploitation in the next 30 days.

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Dovecot Dovecot: before 2.2.36.4 (fixed in 2.2.36.4); from 2.3.0, before 2.3.7.2 (fixed in 2.3.7.2)
  • Dovecot Pigeonhole: before 0.5.7.2 (fixed in 0.5.7.2)
  • Fedoraproject Fedora: version 30 only

Published 2019-08-29. Last modified 2026-06-17.