[manjaro-security] [ASA-202002-6] dovecot: denial of service
rgacogne at archlinux.org
Thu Feb 13 10:29:17 CET 2020
Arch Linux Security Advisory ASA-202002-6
Date : 2020-02-12
CVE-ID : CVE-2020-7046 CVE-2020-7957
Package : dovecot
Type : denial of service
Remote : Yes
Link : https://security.archlinux.org/AVG-1097
The package dovecot before version 184.108.40.206-1 is vulnerable to denial of
Upgrade to 220.127.116.11-1.
# pacman -Syu "dovecot>=18.104.22.168-1"
The problems have been fixed upstream in version 22.214.171.124.
- CVE-2020-7046 (denial of service)
A denial of service has been found in Dovecot before 126.96.36.199, where
lib-smtp doesn't handle truncated command parameters properly,
resulting in infinite loop taking 100% CPU for the process. This
happens for LMTP (where it doesn't matter so much) and also for
submission-login where unauthenticated users can trigger it.
- CVE-2020-7957 (denial of service)
A denial of service have been found in Dovecot before 188.8.131.52, where a
specially crafted e-mail can cause a mailbox to have permanently
inaccessible mail, or the e-mail itself can be stuck in delivery. This
happens because the snippet generation crashes if a message is large
enough that message-parser returns multiple body blocks, the first
block(s) don't contain the full snippet (e.g. full of whitespace) and
the input ends with '>'.
A remote, unauthenticated user can cause a denial of service via a
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: OpenPGP digital signature
More information about the manjaro-security