src:dovecot: multiple dovecot CVEs

Related Vulnerabilities: CVE-2020-12100   CVE-2020-12673   CVE-2020-12674  

Debian Bug report logs - #968302
src:dovecot: multiple dovecot CVEs

version graph

Reported by: Noah Meyerhans <noahm@debian.org>

Date: Wed, 12 Aug 2020 17:45:01 UTC

Severity: grave

Tags: bullseye, security, sid

Found in versions dovecot/1:2.3.4.1-5+deb10u2, dovecot/1:2.3.10.1+dfsg1-2

Fixed in version dovecot/1:2.3.4.1-5+deb10u3

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Dovecot Maintainers <dovecot@packages.debian.org>:
Bug#968302; Package src:dovecot. (Wed, 12 Aug 2020 17:45:03 GMT) (full text, mbox, link).


Acknowledgement sent to Noah Meyerhans <noahm@debian.org>:
New Bug report received and forwarded. Copy sent to Dovecot Maintainers <dovecot@packages.debian.org>. (Wed, 12 Aug 2020 17:45:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Noah Meyerhans <noahm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: src:dovecot: multiple dovecot CVEs
Date: Wed, 12 Aug 2020 10:40:14 -0700
Package: src:dovecot
Version: 1:2.3.10.1+dfsg1-2
Severity: grave
Tags: security bullseye sid
Justification: user security hole

Multiple security issues have been identified in dovecot.  These were addressed
in stable with dovecot 1:2.3.4.1-5+deb10u3 (DSA 4745-1), but need to be tracked
in unstable and testing.

From the DSA:

CVE-2020-12100                                                                                                                                                                                                      
                                                                                                                                                                                                                    
    Receiving mail with deeply nested MIME parts leads to resource                                                                                                                                                  
    exhaustion as Dovecot attempts to parse it.                                                                                                                                                                     
                                                                                                                                                                                                                    
CVE-2020-12673                                                                                                                                                                                                      
                                                                                                                                                                                                                    
    Dovecot's NTLM implementation does not correctly check message                                                                                                                                                  
    buffer size, which leads to a crash when reading past allocation.                                                                                                                                               
                                                                                                                                                                                                                    
CVE-2020-12674                                                                                                                                                                                                      
                                                                                                                                                                                                                    
    Dovecot's RPA mechanism implementation accepts zero-length message,                                                                                                                                             
    which leads to assert-crash later on.                                                                                                                                                                           



Marked as fixed in versions dovecot/1:2.3.4.1-5+deb10u3. Request was from Noah Meyerhans <noahm@debian.org> to control@bugs.debian.org. (Wed, 12 Aug 2020 17:54:03 GMT) (full text, mbox, link).


Marked as found in versions dovecot/1:2.3.4.1-5+deb10u2. Request was from Noah Meyerhans <noahm@debian.org> to control@bugs.debian.org. (Wed, 12 Aug 2020 18:00:02 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Aug 13 10:23:01 2020; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.