Improper Handling of Zip Attachments in Dovecot Software
CVE-2025-59031
4.3MEDIUM
What is CVE-2025-59031?
Dovecot has a vulnerability related to the script used for converting attachments to text, which improperly handles zip-style attachments. This flaw allows an attacker to exploit specially crafted OOXML documents, potentially causing unintended files to be indexed on the system. Consequently, these files may appear in Full-Text Search (FTS) indexes. Users are advised against employing the provided script and are encouraged to utilize safer alternatives such as FTS Tika for file processing to mitigate this risk.
Affected Version(s)
OX Dovecot Pro 0 <= 2.3.0
