An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users’ email messages (and path disclosure).
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24386
Reference (s):
- http://www.openwall.com/lists/oss-security/2021/01/04/4
- https://dovecot.org/pipermail/dovecot-news/2021-January/000450.html
- DEBIAN:DSA-4825
- URL: https://www.debian.org/security/2021/dsa-4825
- FEDORA:FEDORA-2021-c90cb486f7

