Logo
vulnerabilityCVE-2025-59031
Name
CVE-2025-59031
Source
NVD ( link)Debian ( link)
Description
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dovecot
Exploitable

Vulnerability Ratings#


4.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.3.21.1
Exploitable
buildroot
master
2.3.21.1
Exploitable
openwrt
master
2.3.21-r1
Exploitable
yocto
kirkstone
2.3.14
Exploitable
yocto
master
2.4.4
Not Affected
yocto
scarthgap
2.3.21.1
Exploitable