CVE-2020-10958: Dovecot
Medium severity, CVSS 5.3. EPSS: 6.1% chance of exploitation in the next 30 days.
In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.
Affected products
- Dovecot Dovecot: before 2.3.10.1 (fixed in 2.3.10.1)
Published 2020-05-18. Last modified 2026-06-17.