ALAS2-2019-1347

Related Vulnerabilities: CVE-2019-11500  

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.(CVE-2019-11500)

ALAS2-2019-1347


Amazon Linux 2 Security Advisory: ALAS-2019-1347
Advisory Release Date: 2019-11-04 22:10 Pacific
Advisory Updated Date: 2019-11-07 00:27 Pacific
Severity: Important
References: CVE-2019-11500 

Issue Overview:

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.(CVE-2019-11500)


Affected Packages:

dovecot


Issue Correction:
Run yum update dovecot to update your system.

New Packages:
aarch64:
    dovecot-2.2.36-3.amzn2.1.aarch64
    dovecot-pigeonhole-2.2.36-3.amzn2.1.aarch64
    dovecot-pgsql-2.2.36-3.amzn2.1.aarch64
    dovecot-mysql-2.2.36-3.amzn2.1.aarch64
    dovecot-devel-2.2.36-3.amzn2.1.aarch64
    dovecot-debuginfo-2.2.36-3.amzn2.1.aarch64

i686:
    dovecot-2.2.36-3.amzn2.1.i686
    dovecot-pigeonhole-2.2.36-3.amzn2.1.i686
    dovecot-pgsql-2.2.36-3.amzn2.1.i686
    dovecot-mysql-2.2.36-3.amzn2.1.i686
    dovecot-devel-2.2.36-3.amzn2.1.i686
    dovecot-debuginfo-2.2.36-3.amzn2.1.i686

src:
    dovecot-2.2.36-3.amzn2.1.src

x86_64:
    dovecot-2.2.36-3.amzn2.1.x86_64
    dovecot-pigeonhole-2.2.36-3.amzn2.1.x86_64
    dovecot-pgsql-2.2.36-3.amzn2.1.x86_64
    dovecot-mysql-2.2.36-3.amzn2.1.x86_64
    dovecot-devel-2.2.36-3.amzn2.1.x86_64
    dovecot-debuginfo-2.2.36-3.amzn2.1.x86_64