GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sun Sep 06, 2020 2:26 am Post subject: [ GLSA 202009-02 ] Dovecot |
|
|
Gentoo Linux Security Advisory
Title: Dovecot: Multiple vulnerabilities (GLSA 202009-02)
Severity: normal
Exploitable: remote
Date: 2020-09-06
Bug(s): #736617
ID: 202009-02
Synopsis
Multiple vulnerabilities have been found in Dovecot, the worst of
which could allow remote attackers to cause a Denial of Service condition.
Background
Dovecot is an open source IMAP and POP3 email server.
Affected Packages
Package: net-mail/dovecot
Vulnerable: < 2.3.11.3
Unaffected: >= 2.3.11.3
Architectures: All supported architectures
Description
It was discovered that Dovecot incorrectly handled deeply nested MIME
parts, incorrectly handled memory when using NTLM, and incorrectly
handled zero-length messages.
Impact
A remote attacker could send a specially crafted mail or send specially
crafted authentication requests possibly resulting in a Denial of Service
condition.
Workaround
There is no known workaround at this time.
Resolution
All Dovecot users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-mail/dovecot-2.3.11.3"
|
References
CVE-2020-12100
CVE-2020-12673
CVE-2020-12674 |
|