Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia: 2020-0222 Critical Security Update for Dovecot Service Crash

mageia
Calendar Grey May 24, 2020
Dist Mageia Esm H88
Dovecot security enhancement for Mageia resolves several service interruptions caused by incorrectly formatted commands. Significant patches implemented.
Dovecot has been updated to fix several security issues

Summary

Dovecot has been updated to fix several security issues.
Sending malformed NOOP command causes crash in submission, submission-login or lmtp service (CVE-2020-10957).
Sending command followed by sufficient number of newlines triggers a use-after-free bug that might crash submission-login, submission or lmtp service (CVE-2020-10958).
Sending mail with empty quoted localpart causes submission or lmtp component to crash (CVE-2020-10967).

References

- https://bugs.mageia.org/show_bug.cgi?id=26644

- https://www.openwall.com/lists/oss-security/2020/05/18/1

- https://www.cve.org/CVERecord?id=CVE-2020-10957

- https://www.cve.org/CVERecord?id=CVE-2020-10958

- https://www.cve.org/CVERecord?id=CVE-2020-10967

Resolution

SRPMS

- 7/core/dovecot-2.3.10.1-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 24 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0222.html
Type: security
CVE: CVE-2020-10957, CVE-2020-10958, CVE-2020-10967

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here