OESA-2021-1270
Dashboard / Vulnerabilities / OESA-2021-1270
OESA-2021-1270
Summary: dovecot security update
Details: Dovecot is an IMAP server for Linux/UNIX-like systemsa wrapper package that will just handle common things for all versioned dovecot packages. Security Fix(es): The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.(CVE-2020-28200) The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.(CVE-2021-33515)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1270, https://nvd.nist.gov/vuln/detail/CVE-2020-28200, https://nvd.nist.gov/vuln/detail/CVE-2021-33515
Affected packages
Package
Name: dovecot
Purl: pkg:rpm/openEuler/dovecot&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
