#14460: dovecot-2.3.13
-------------------------+------------------------
 Reporter:  renodr       |       Owner:  blfs-book
     Type:  enhancement  |      Status:  new
 Priority:  normal       |   Milestone:  10.1
Component:  BOOK         |     Version:  SVN
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------

Comment (by renodr):

 '''CVE-2020-24386'''

 {{{
 Open-Xchange Security Advisory 2021-01-04

 Product: Dovecot
 Vendor: OX Software GmbH
 Internal reference: DOP-2009 (Bug ID)
 Vulnerability type: CWE-150: Improper Neutralization of Escape, Meta, or
 Control Sequences
 Vulnerable version: 2.2.26-2.3.11.3
 Vulnerable component: imap
 Report confidence: Confirmed
 Solution status: Fixed by Vendor
 Fixed version: 2.3.13
 Vendor notification: 2020-08-17
 Solution date: 2020-08-27
 Public disclosure: 2021-01-04
 CVE reference: CVE-2020-24386
 CVSS: 8.2 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N)

 Vulnerability Details:

 When imap hibernation is active, an attacker can cause Dovecot to
 discover file
 system directory structure and access other users' emails using
 specially crafted
 command. The attacker must have valid credentials to access the mail
 server.

 Risk:

 Attacker can access other users' emails and filesystem information.

 Workaround:

 Operators can choose to disable IMAP hibernation. IMAP hibernation is
 not on by
 default. To ensure imap hibernation is disabled, make sure
 imap_hibernate_timeout
 is set to 0 or unset.

 Solution:

 Operators should update to 2.3.13 or later version.
 }}}

 This one is particularly serious. If this feature is enabled, it allows a
 user to access other users' mail.

--
Ticket URL: <http://wiki.linuxfromscratch.org/blfs/ticket/14460#comment:2>
BLFS Trac <http://wiki.linuxfromscratch.org/blfs>
Beyond Linux From Scratch
-- 
http://lists.linuxfromscratch.org/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page

Reply via email to