USN-4993-1
Dashboard / Vulnerabilities / USN-4993-1
USN-4993-1
Summary: dovecot vulnerabilities
Details: Kirin discovered that Dovecot incorrectly escaped kid and azp fields in JWT tokens. A local attacker could possibly use this issue to validate tokens using arbitrary keys. This issue only affected Ubuntu 20.10 and Ubuntu 21.04. (CVE-2021-29157) Fabian Ising and Damian Poddebniak discovered that Dovecot incorrectly handled STARTTLS when using the SMTP submission service. A remote attacker could possibly use this issue to inject plaintext commands before STARTTLS negotiation. (CVE-2021-33515)
References: https://ubuntu.com/security/notices/USN-4993-1, https://ubuntu.com/security/CVE-2021-29157, https://ubuntu.com/security/CVE-2021-33515
Affected packages
Package
Name: dovecot
Purl: pkg:deb/ubuntu/dovecot@1:2.3.7.2-1ubuntu3.4?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
