OESA-2021-1042
Dashboard / Vulnerabilities / OESA-2021-1042
Summary: dovecot security update
Details: Security Fix(es): Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.(CVE-2020-25275) An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).(CVE-2020-24386)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1042, https://nvd.nist.gov/vuln/detail/CVE-2020-25275, https://nvd.nist.gov/vuln/detail/CVE-2020-24386
Affected packages
Package
Name: dovecot
Purl: pkg:rpm/openEuler/dovecot&distro=openEuler-20.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
