Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 31: FEDORA-2020-b60344c987 Critical DoS Advisory for Dovecot

fedora
Calendar Grey May 27, 2020
Dist Fedora Esm H88
The latest Dovecot security notice emphasizes essential patches addressing severe gaps that could result in service disruptions on Fedora 31.
- CVE-2020-10957: lmtp/submission: A client can crash the server by sending a NOOP command with an invalid string parameter

Summary

Dovecot is an IMAP server for Linux/UNIX-like systems, written with security

primarily in mind. It also contains a small POP3 server. It supports mail

in either of maildir or mbox formats.

The SQL drivers and authentication plug-ins are in their subpackages.

- CVE-2020-10957: lmtp/submission: A client can crash the server by sending a

NOOP command with an invalid string parameter. This occurs particularly for a

parameter that doesn't start with a double quote. This applies to all SMTP

services, including submission-login, which makes it possible to crash the

submission service without authentication. - CVE-2020-10958: lmtp/submission:

Sending many invalid or unknown commands can cause the server to access freed

memory, which can lead to a server crash. This happens when the server closes

the connection with a "421 Too many invalid commands" error. The bad command

limit depends on the service (lmtp or submission) and varies between 10 to

20 bad commands. - CVE-2020-10967: lmtp/submission: Issuing the RCPT command

with an address that has the empty quoted string as local-part causes the

lmtp service to crash.

* Mon May 18 2020 Michal Hlavinka - 1:2.3.10.1-1

- dovecot updated to 2.3.10.1

- fixes CVE-2020-10967, CVE-2020-10958, CVE-2020-10957

[ 1 ] Bug #1834317 - CVE-2020-10957 dovecot: malformed NOOP commands leads to DoS

https://bugzilla.redhat.com/show_bug.cgi?id=1834317

[ 2 ] Bug #1834323 - CVE-2020-10958 dovecot: command followed by sufficient number of newlines leads to use-after-free

https://bugzilla.redhat.com/show_bug.cgi?id=1834323

[ 3 ] Bug #1834326 - CVE-2020-10967 dovecot: sending mail with empty quoted localpart leads to DoS

https://bugzilla.redhat.com/show_bug.cgi?id=1834326

su -c 'dnf upgrade --advisory FEDORA-2020-b60344c987' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 2.3.10.1
Release: 1.fc31
Summary: Secure imap and pop3 server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here