Headline
CVE-2019-11499: Dovecot | Security
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.
Security
Dovecot was designed since the beginning with security in mind and with many ways to provide privilege separation. Although the code is written with C, it’s a little bit special C variant that makes it much more difficult to write security holes accidentally than with most other C-based projects.
Please see https://www.dovecot.org/bugreport-mail for more information how to report bugs.