Dovecot IMAP server versions 2.2 and 2.3 suffer from denial of service and resource exhaustion vulnerabilities.
94b0aee67b11da7bd129e38ffb00abe29b299d02c054b3f6993f853db9c89a1c
Dovecot IMAP server versions 2.2 and 2.3 have an issue where a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue.
110c1562e949571c822c2ff350b36b50c9dbaf0d176f46ef0289ae7411955fe8
Dovecot versions 2.2.26 through 2.3.11.3 suffer from a bypass issue. When imap hibernation is active, an attacker can cause Dovecot to discover file system directory structure and access other users' emails using a specially crafted command. The attacker must have valid credentials to access the mail server.
5e5468067fc35516788b52ac2a4e75207c4c6d4b1f0ea93176e970b293daf7d6
Dovecot versions 2.3.11 through 2.3.11.3 suffer from a denial of service condition related to MIME parsing.
3eac47b5a5d3ef5ce3b165410088b1db4617e678b8f7dc67fe4f1fd3152672a4