Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Fedora 33: FEDORA-2020-b8ebc4201e Critical: Dovecot Memory Crashes

fedora
Calendar Grey September 25, 2020
Dist Fedora Esm H88
Stay informed with vital updates on Dovecot for Fedora 33 that tackle significant stack memory vulnerabilities and system crashes, featuring necessary patch implementations.
CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory

Summary

Dovecot is an IMAP server for Linux/UNIX-like systems, written with security

primarily in mind. It also contains a small POP3 server. It supports mail

in either of maildir or mbox formats.

The SQL drivers and authentication plug-ins are in their subpackages.

CVE-2020-12100: Parsing mails with a large number of MIME parts could

have resulted in excessive CPU usage or a crash due to running out of

stack memory. CVE-2020-12673: Dovecot's NTLM implementation does not

correctly check message buffer size, which leads to reading past

allocation which can lead to crash. CVE-2020-10967: lmtp/submission:

Issuing the RCPT command with an address that has the empty quoted string

as local-part causes the lmtp service to crash. CVE-2020-12674:

Dovecot's RPA mechanism implementation accepts zero-length message, which

leads to assert-crash later on.

* Wed Sep 2 2020 Michal Hlavinka - 1:2.3.11.3-5

- fix gssapi issue

* Wed Aug 26 2020 Michal Hlavinka - 1:2.3.11.3-4

- fix FTBFS on 32bit systems

* Mon Aug 17 2020 Jeff Law - 1:2.3.11.3-2

- Disable LTO

* Sat Aug 15 2020 Michal Hlavinka - 1:2.3.11.3-1

- CVE-2020-12100: Parsing mails with a large number of MIME parts could

have resulted in excessive CPU usage or a crash due to running out of

stack memory.

- CVE-2020-12673: Dovecot's NTLM implementation does not correctly check

message buffer size, which leads to reading past allocation which can

lead to crash.

- CVE-2020-10967: lmtp/submission: Issuing the RCPT command with an

address that has the empty quoted string as local-part causes the lmtp

service to crash.

- CVE-2020-12674: Dovecot's RPA mechanism implementation accepts

zero-length message, which leads to assert-crash later on.

* Sat Aug 1 2020 Fedora Release Engineering - 1:2.3.10.1-3

- Second attempt - Rebuilt for

https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild

* Mon Jul 27 2020 Fedora Release Engineering - 1:2.3.10.1-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild

[ 1 ] Bug #1868539 - CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1868539

[ 2 ] Bug #1868540 - CVE-2020-12673 dovecot: Out of bound reads in dovecot NTLM implementation [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1868540

[ 3 ] Bug #1868541 - CVE-2020-12674 dovecot: Crash due to assert in RPA implementation [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1868541

su -c 'dnf upgrade --advisory FEDORA-2020-b8ebc4201e' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 2.3.11.3
Release: 5.fc33
Summary: Secure imap and pop3 server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here