Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25275
Reference (s):
- http://www.openwall.com/lists/oss-security/2021/01/04/3
- https://dovecot.org/pipermail/dovecot-news/2021-January/000451.html
- DEBIAN:DSA-4825
- URL: https://www.debian.org/security/2021/dsa-4825
- FEDORA:FEDORA-2021-c90cb486f7