Logo
vulnerabilityCVE-2025-59028
Name
CVE-2025-59028
Source
NVD ( link)Debian ( link)
Description
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty on large deployments). No publicly available exploits are known.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dovecot
Exploitable

Vulnerability Ratings#


5.3
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.3.21.1
Exploitable
buildroot
master
2.3.21.1
Exploitable
openwrt
master
2.3.21-r1
Exploitable
openwrt
openwrt-25.12
2.3.21-r1
Exploitable
yocto
kirkstone
2.3.14
Exploitable
yocto
master
2.4.4
Not Affected