Alerts This Week
Warning Icon 1 469
Alerts This Week
Warning Icon 1 469

Fedora 31 Dovecot: 2020-10a58fda28 Critical DoS and Crash Fix

fedora
Calendar Grey February 20, 2020
Dist Fedora Esm H88
Dovecot received an important update addressing severe DoS and crash vulnerabilities in Fedora 31, as detailed in advisory FEDORA-2020-10b58fda29.
- dovecot updated to 2.3.9.3 - fixes CVE-2020-7046: Truncated UTF-8 can be used to DoS submission-login and lmtp processes

Summary

Dovecot is an IMAP server for Linux/UNIX-like systems, written with security

primarily in mind. It also contains a small POP3 server. It supports mail

in either of maildir or mbox formats.

The SQL drivers and authentication plug-ins are in their subpackages.

- dovecot updated to 2.3.9.3 - fixes CVE-2020-7046: Truncated UTF-8 can be used

to DoS submission-login and lmtp processes. - fixes CVE-2020-7957: Specially

crafted mail can crash snippet generation.

* Wed Feb 12 2020 Michal Hlavinka - 1:2.3.9.3-1

- dovecot updated to 2.3.9.3

- fixes CVE-2020-7046: Truncated UTF-8 can be used to DoS

submission-login and lmtp processes.

- fixes CVE-2020-7957: Specially crafted mail can crash snippet generation.

* Tue Jan 28 2020 Fedora Release Engineering - 1:2.3.9.2-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild

* Thu Dec 19 2019 Michal Hlavinka - 1:2.3.9.2-1

- CVE-2019-19722: Mails with group addresses in From or To fields

caused crash in push notification drivers.

* Wed Dec 4 2019 Michal Hlavinka - 1:2.3.9-1

- dovecot updated to 2.3.9, pigeonhole updated to 0.5.9

* Thu Oct 10 2019 Michal Hlavinka - 1:2.3.8-1

- dovecot updated to 2.3.8, pigeonhole 0.5.8

su -c 'dnf upgrade --advisory FEDORA-2020-10a58fda28' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 2.3.9.3
Release: 1.fc31
Summary: Secure imap and pop3 server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here