Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. CVE-2020-12673: Dovecot's NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-10967: lmtp/submission:. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-d737c57172 2020-10-13 20:34:18.297189 --------------------------------------------------------------------------------Name : dovecot Product : Fedora 32 Version : 2.3.11.3 Release : 5.fc32 URL : https://dovecot.org/ Summary : Secure imap and pop3 server Description : Dovecot is an IMAP server for Linux/UNIX-like systems, written with security primarily in mind. It also contains a small POP3 server. It supports mail in either of maildir or mbox formats. The SQL drivers and authentication plug-ins are in their subpackages. --------------------------------------------------------------------------------Update Information: CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. CVE-2020-12673: Dovecot's NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-10967: lmtp/submission: Issuing the RCPT command with an address that has the empty quoted string as local-part causes the lmtp service to crash. CVE-2020-12674: Dovecot's RPA mechanism implementation accepts zero-length message, which leads to assert-crash later on. --------------------------------------------------------------------------------ChangeLog: * Wed Sep 2 2020 Michal Hlavinka - 1:2.3.11.3-5 - fix gssapi issue * Wed Aug 26 2020 Michal Hlavinka - 1:2.3.11.3-4 - fix FTBFS on 32bitsystems * Mon Aug 17 2020 Jeff Law - 1:2.3.11.3-2 - Disable LTO * Sat Aug 15 2020 Michal Hlavinka - 1:2.3.11.3-1 - CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. - CVE-2020-12673: Dovecot's NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. - CVE-2020-10967: lmtp/submission: Issuing the RCPT command with an address that has the empty quoted string as local-part causes the lmtp service to crash. - CVE-2020-12674: Dovecot's RPA mechanism implementation accepts zero-length message, which leads to assert-crash later on. * Sat Aug 1 2020 Fedora Release Engineering - 1:2.3.10.1-3 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Mon Jul 27 2020 Fedora Release Engineering - 1:2.3.10.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1868539 - CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1868539 [ 2 ] Bug #1868540 - CVE-2020-12673 dovecot: Out of bound reads in dovecot NTLM implementation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1868540 [ 3 ] Bug #1868541 - CVE-2020-12674 dovecot: Crash due to assert in RPA implementation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1868541 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-d737c57172' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for dovecot22 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2274-1 Rating: important References: #1174922 #1174923 Cross-References: CVE-2020-12673 CVE-2020-12674 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Enterprise Storage 5 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for dovecot22 fixes the following issues: - CVE-2020-12673: improper implementation of NTLM does not check message buffer size (bsc#1174922). - CVE-2020-12674: improper implementation of RPA mechanism (bsc#1174923). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patchSUSE-OpenStack-Cloud-Crowbar-9-2020-2274=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-2274=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2020-2274=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2020-2274=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-2274=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-2274=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2020-2274=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2020-2274=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2020-2274=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-2274=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2020-2274=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2020-2274=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2020-2274=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2020-2274=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2020-2274=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2020-2274=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2020-2274=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE OpenStack Cloud 9 (x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE OpenStack Cloud 8 (x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE OpenStack Cloud 7 (s390x x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE LinuxEnterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 dovecot22-devel-2.2.31-19.22.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - SUSE Enterprise Storage 5 (aarch64 x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 - HPE Helion Openstack 8 (x86_64): dovecot22-2.2.31-19.22.1 dovecot22-backend-mysql-2.2.31-19.22.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.22.1 dovecot22-backend-pgsql-2.2.31-19.22.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.22.1 dovecot22-backend-sqlite-2.2.31-19.22.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.22.1 dovecot22-debuginfo-2.2.31-19.22.1 dovecot22-debugsource-2.2.31-19.22.1 References: https://www.suse.com/security/cve/CVE-2020-12673.html https://www.suse.com/security/cve/CVE-2020-12674.html https://bugzilla.suse.com/1174922 https://bugzilla.suse.com/1174923 _______________________________________________ sle-security-updates mailing list
Fixes a problem with NTLM authentication in evolution-connector with usernames of the form DOMAINUSERNAME. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-817 2005-08-26 ---------------------------------------------------------------------Product : Fedora Core 3 Name : libsoup Version : 2.2.2 Release : 2.FC3 Summary : Soup, an HTTP library implementation Description : Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it). ---------------------------------------------------------------------Update Information: Fixes a problem with NTLM authentication in evolution-connector with usernames of the form DOMAINUSERNAME ---------------------------------------------------------------------* Tue Jun 14 2005 David Malcolm - 2.2.2-2.FC3 - add patch for NTLM domains (#159901) ---------------------------------------------------------------------This update can be downloaded from: 1254f5f3fe9dda6ec15c518992876011 SRPMS/libsoup-2.2.2-2.FC3.src.rpm f71b7a6279fd726e2b184912b17ac406 x86_64/libsoup-2.2.2-2.FC3.x86_64.rpm f71fad6a2ca28e14aed211be3859e96a x86_64/libsoup-devel-2.2.2-2.FC3.x86_64.rpm a9ae49ead5feeef9b57ab9b3c6c35533 x86_64/debug/libsoup-debuginfo-2.2.2-2.FC3.x86_64.rpm e357c1cee4654f901924debf4c75e7f1 x86_64/libsoup-2.2.2-2.FC3.i386.rpm e357c1cee4654f901924debf4c75e7f1 i386/libsoup-2.2.2-2.FC3.i386.rpm cced242890362419617195a4206156ee i386/libsoup-devel-2.2.2-2.FC3.i386.rpm 5318926f71eba2684ae4e229c4a1eb66 i386/debug/libsoup-debuginfo-2.2.2-2.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.