Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202009-02 ] Dovecot: Multiple vulnerabilities
Date: Sun, 06 Sep 2020 00:30:06
Message-Id: 5e16020b-084e-679e-f340-3b213acc5c01@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202009-02
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Dovecot: Multiple vulnerabilities
9 Date: September 06, 2020
10 Bugs: #736617
11 ID: 202009-02
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Dovecot, the worst of which
19 could allow remote attackers to cause a Denial of Service condition.
20
21 Background
22 ==========
23
24 Dovecot is an open source IMAP and POP3 email server.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-mail/dovecot < 2.3.11.3 >= 2.3.11.3
33
34 Description
35 ===========
36
37 It was discovered that Dovecot incorrectly handled deeply nested MIME
38 parts, incorrectly handled memory when using NTLM, and incorrectly
39 handled zero-length messages.
40
41 Impact
42 ======
43
44 A remote attacker could send a specially crafted mail or send specially
45 crafted authentication requests possibly resulting in a Denial of
46 Service condition.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All Dovecot users should upgrade to the latest version:
57
58 # emerge --sync
59 # emerge --ask --oneshot --verbose ">=net-mail/dovecot-2.3.11.3"
60
61 References
62 ==========
63
64 [ 1 ] CVE-2020-12100
65 https://nvd.nist.gov/vuln/detail/CVE-2020-12100
66 [ 2 ] CVE-2020-12673
67 https://nvd.nist.gov/vuln/detail/CVE-2020-12673
68 [ 3 ] CVE-2020-12674
69 https://nvd.nist.gov/vuln/detail/CVE-2020-12674
70
71 Availability
72 ============
73
74 This GLSA and any updates to it are available for viewing at
75 the Gentoo Security Website:
76
77 https://security.gentoo.org/glsa/202009-02
78
79 Concerns?
80 =========
81
82 Security is a primary focus of Gentoo Linux and ensuring the
83 confidentiality and security of our users' machines is of utmost
84 importance to us. Any security concerns should be addressed to
85 security@g.o or alternatively, you may file a bug at
86 https://bugs.gentoo.org.
87
88 License
89 =======
90
91 Copyright 2020 Gentoo Foundation, Inc; referenced text
92 belongs to its owner(s).
93
94 The contents of this document are licensed under the
95 Creative Commons - Attribution / Share Alike license.
96
97 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature