CVE-2016-8652

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
17/02/2017
Last modified:
20/04/2025

Description

The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* 2.2.27 (including)