CVE-2020-12100: Receiving mail with deeply nested MIME parts leads to resource
exhaustion as Dovecot attempts to parse it.
CVE-2020-12673: Dovecot's NTLM implementation does not correctly check message
buffer size, which leads to reading past allocation which can lead to crash.
CVE-2020-12674: Dovecot's RPA mechanism implementation accepts zero-length
message, which leads to assert-crash later on.
- https://bugs.mageia.org/show_bug.cgi?id=27099
- https://dovecot.org/pipermail/dovecot-news/2020-August/000441.html
- https://dovecot.org/pipermail/dovecot-news/2020-August/000442.html
- https://dovecot.org/pipermail/dovecot-news/2020-August/000443.html
- https://www.cve.org/CVERecord?id=CVE-2020-12100
- https://www.cve.org/CVERecord?id=CVE-2020-12673
- https://www.cve.org/CVERecord?id=CVE-2020-12674
- 7/core/dovecot-2.3.11.3-1.mga7
Get the latest Linux and open source security news straight to your inbox.