Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia: 2020-0330 Moderate: Dovecot Security Risks and Fixes

mageia
Calendar Grey August 18, 2020
Dist Mageia Esm H88
Dovecot security enhancements for Mageia address memory leak and NTLM vulnerabilities, released on 18 Aug 2020.
CVE-2020-12100: Receiving mail with deeply nested MIME parts leads to resource exhaustion as Dovecot attempts to parse it

Summary

CVE-2020-12100: Receiving mail with deeply nested MIME parts leads to resource exhaustion as Dovecot attempts to parse it. CVE-2020-12673: Dovecot's NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-12674: Dovecot's RPA mechanism implementation accepts zero-length message, which leads to assert-crash later on.

References

- https://bugs.mageia.org/show_bug.cgi?id=27099

- https://dovecot.org/pipermail/dovecot-news/2020-August/000441.html

- https://dovecot.org/pipermail/dovecot-news/2020-August/000442.html

- https://dovecot.org/pipermail/dovecot-news/2020-August/000443.html

- https://www.cve.org/CVERecord?id=CVE-2020-12100

- https://www.cve.org/CVERecord?id=CVE-2020-12673

- https://www.cve.org/CVERecord?id=CVE-2020-12674

Resolution

SRPMS

- 7/core/dovecot-2.3.11.3-1.mga7

Publication date: 18 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0330.html
Type: security
CVE: CVE-2020-12100, CVE-2020-12673, CVE-2020-12674

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here