Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 4745-1] dovecot security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 4745-1] dovecot security update


Chronologisch Thread 
  • From: Salvatore Bonaccorso <carnil AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 4745-1] dovecot security update
  • Date: Wed, 12 Aug 2020 15:52:48 +0000
  • List-archive: https://lists.debian.org/msgid-search/E1k5t3Y-00083t-O0 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=8wEc7WAxyYOBHHmQUTCy3qs+HIAk9jV5WJQZeV3A8PI=; b=pJ UJroCJqaeBkbbZMBslS0k3bqUy2ZT6dTebyZCFHZ9L8ND7CB3dYvaePrOg7YEZxWLKt68NQebqIDB JmQh+fSjZ23CwDfpBCU+SQxsZj658GOuPvcJAn8cd3eKPcMoGXSkSxxgtaKCH4DWOXKo8NiGDkZ7o MCnZ1OW4vua2WnGEkwOUa4QaYsatyMIt11rkAjumIzpffhfgVktNhclck3YTo8mAnHqdjRw4GRJjh kNLaiwh2N7xXdeC+4Pg+o+rf23UjVWh9EV3x9Gfw8nAoojThtqdXYAvlmFyWOzL5J49KAWL7cKiH/ ImXWcGZNEhX46OKdIJfWad65jdVT2TPA==;
  • Old-return-path: <carnil AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Wed, 12 Aug 2020 15:53:05 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <rtTKlR0QXyE.A.05.hBBNfB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4745-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 12, 2020 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : dovecot
CVE ID : CVE-2020-12100 CVE-2020-12673 CVE-2020-12674

Several vulnerabilities have been discovered in the Dovecot email
server.

CVE-2020-12100

Receiving mail with deeply nested MIME parts leads to resource
exhaustion as Dovecot attempts to parse it.

CVE-2020-12673

Dovecot's NTLM implementation does not correctly check message
buffer size, which leads to a crash when reading past allocation.

CVE-2020-12674

Dovecot's RPA mechanism implementation accepts zero-length message,
which leads to assert-crash later on.

For the stable distribution (buster), these problems have been fixed in
version 1:2.3.4.1-5+deb10u3.

We recommend that you upgrade your dovecot packages.

For the detailed security status of dovecot please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/dovecot

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl80EBZfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0RvhRAAonS/PXa8HtA3Mb2b4wNjVZYj1CwXQTYIDivYLVtKP57qPshMYR7A/mLj
WOwU6YUH6isCrNBk1EkyZCyKw968S5Cb0G2+UjadlELIJ+rNODpXMRRmh0MSSQ5z
7IimtwU/Fhlb097ppjR6uf8emN2pyTD5qA2piwgz0kYVwLMaxDE6ZoRdtapxZ2vs
s9Bzat4TqPQXe5s/6+pjLceHEa2pFxm4tRueWvN4YfUkPkySSriJMrUSg0r8TXZ4
UEVCk3r3UB2nzvBxTRTaCwrmX5pSBaMPkv+Tpb1sgIAn5IfzNU17s4RAY17gRXOp
f9IZtkR+IehEcgn7495XeGKsqvGjUeVD6x9pqfNMEYWMZgtK7PgxJBKkP+i4Yr7p
AEA/ZRwd3FZFh7Vu4YwJUO+bnDmZglmsmHVw5FQzASUdY/6T9aLPBwZKmMoL0z6t
Bdi9LTX9RJNTf8Okjf/R689IQkPqjBLE/gouWnHBQs9cUjQdGlbwDLZKb3Nf+6YF
Y06hkWym7pLGSBL2aS05kQacJIji+Mj1/23wMRPOStwj/IygCv1Q8rLJlUtU8/sF
rP5hBMRy56pqVKk4WHpBGNLBJNL7wLQBTFg0oJxkwS98I5fxJRJjtRRz3Y2G6Vcu
Q2qM469h9BLftuU0w72RRJB5PZksYJkIbqsE5EH02VkSAxwxXhM=
=z0rs
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 4745-1] dovecot security update, Salvatore Bonaccorso, 12.08.2020

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang