Gentoo Archives: gentoo-announce

From: Sam James <sam@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202101-01 ] Dovecot: Multiple vulnerabilities
Date: Sun, 10 Jan 2021 09:25:19
Message-Id: F93FE9F7-D719-4FE5-AE96-E32769D11F74@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202101-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Dovecot: Multiple vulnerabilities
9 Date: January 10, 2021
10 Bugs: #763525
11 ID: 202101-01
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Dovecot, the worst of which
19 could allow remote attackers to cause a Denial of Service condition.
20
21 Background
22 ==========
23
24 Dovecot is an open source IMAP and POP3 email server.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-mail/dovecot < 2.3.13 >= 2.3.13
33
34 Description
35 ===========
36
37 Multiple vulnerabilities have been discovered in Dovecot. Please review
38 the CVE identifiers referenced below for details.
39
40 Impact
41 ======
42
43 A remote attacker could send a specially crafted mail or send a
44 specially crafted IMAP command possibly resulting in a Denial of
45 Service condition or an authenticated remote attacker might be able to
46 discover the file system directory structure and access other users'
47 emails.
48
49 Workaround
50 ==========
51
52 The information disclosure vulnerability can be mitigated by disabling
53 IMAP hibernation feature which isn't enabled by default.
54
55 Resolution
56 ==========
57
58 All Dovecot users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=net-mail/dovecot-2.3.13"
62
63 References
64 ==========
65
66 [ 1 ] CVE-2020-24386
67 https://nvd.nist.gov/vuln/detail/CVE-2020-24386
68 [ 2 ] CVE-2020-25275
69 https://nvd.nist.gov/vuln/detail/CVE-2020-25275
70
71 Availability
72 ============
73
74 This GLSA and any updates to it are available for viewing at
75 the Gentoo Security Website:
76
77 https://security.gentoo.org/glsa/202101-01
78
79 Concerns?
80 =========
81
82 Security is a primary focus of Gentoo Linux and ensuring the
83 confidentiality and security of our users' machines is of utmost
84 importance to us. Any security concerns should be addressed to
85 security@g.o or alternatively, you may file a bug at
86 https://bugs.gentoo.org.
87
88 License
89 =======
90
91 Copyright 2021 Gentoo Foundation, Inc; referenced text
92 belongs to its owner(s).
93
94 The contents of this document are licensed under the
95 Creative Commons - Attribution / Share Alike license.
96
97 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature