openSUSE-SU-2021:0072-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0072-1
openSUSE-SU-2021:0072-1
Summary: Security update for dovecot23
Details: This update for dovecot23 fixes the following issues: Security issues fixed: - CVE-2020-12100: Fixed a resource exhaustion caused by deeply nested MIME parts (bsc#1174920). - CVE-2020-24386: Fixed an issue with IMAP hibernation that allowed users to access other users' emails (bsc#1180405). - CVE-2020-25275: Fixed a crash when the 10000th MIME part was message/rfc822 (bsc#1180406). Non-security issues fixed: - Pigeonhole was updated to version 0.5.11. - Dovecot was updated to version 2.3.11.3. This update was imported from the SUSE:SLE-15-SP1:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/DUR6FYAW4F7DJJAFNZ7FNLNEQNDU6ZEZ/, https://bugzilla.suse.com/1174920, https://bugzilla.suse.com/1180405, https://bugzilla.suse.com/1180406, https://www.suse.com/security/cve/CVE-2020-12100, https://www.suse.com/security/cve/CVE-2020-24386, https://www.suse.com/security/cve/CVE-2020-25275
Affected packages
Package
Name: dovecot23
Purl: pkg:rpm/opensuse/dovecot23&distro=openSUSE%20Leap%2015.1
Affected ranges
Type: ECOSYSTEM
Events:
