In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/Live-Hack-CVE/CVE-2020-12100