Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-69869.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-69869
Upstream
  • CVE-2024-25584
Published
2024-09-06T15:15:12Z
Modified
2026-04-21T04:36:15.808567Z
Summary
CVE-2024-25584 affecting package dovecot 2.3.20-1
Details

Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails. Upgrade to latest released version. No publicly available exploits are known.

References

Affected packages

Azure Linux:2 / dovecot

Package

Name
dovecot
Purl
pkg:rpm/azure-linux/dovecot

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.3.20-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-69869.json"