CVE-2008-4907

Dovecot 1.1.4 and 1.1.5 - Denial of Service via Malformed From Address in IMAP FETCH ENVELOPE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4907. PoCs published by anonymous.

AI-analyzed exploit summary This is a writeup describing a remote denial-of-service vulnerability in Dovecot 1.1.4 and 1.1.5. The issue is triggered by a malformed 'From:' header in an email, causing a crash when the IMAP client uses the FETCH ENVELOPE command.

Description

The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

Exploits (1)

exploitdb WRITEUP VERIFIED
by anonymous · textdoslinux
https://www.exploit-db.com/exploits/32551

This is a writeup describing a remote denial-of-service vulnerability in Dovecot 1.1.4 and 1.1.5. The issue is triggered by a malformed 'From:' header in an email, causing a crash when the IMAP client uses the FETCH ENVELOPE command.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Dovecot 1.1.4, 1.1.5
No auth needed
Prerequisites: IMAP client using FETCH ENVELOPE command · Ability to send crafted email to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Various Sources mailing-list x_refsource_mlist
http://www.dovecot.org/list/dovecot-news/2008-October/000089.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33149
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46227
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-666-1
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31997
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200812-16.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32677
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32479

Scores

EPSS 0.1429
EPSS Percentile 94.5%

Details

CWE
CWE-20
Status published
Products (2)
dovecot/dovecot 1.1.4
dovecot/dovecot 1.1.5
Published Nov 04, 2008
Tracked Since Feb 18, 2026