Package: src:dovecot
Version: 1:2.3.10.1+dfsg1-2
Severity: grave
Tags: security bullseye sid
Justification: user security hole

Multiple security issues have been identified in dovecot.  These were addressed
in stable with dovecot 1:2.3.4.1-5+deb10u3 (DSA 4745-1), but need to be tracked
in unstable and testing.

>From the DSA:

CVE-2020-12100                                                                  
                                                                                
                                                    
                                                                                
                                                                                
                                                    
    Receiving mail with deeply nested MIME parts leads to resource              
                                                                                
                                                    
    exhaustion as Dovecot attempts to parse it.                                 
                                                                                
                                                    
                                                                                
                                                                                
                                                    
CVE-2020-12673                                                                  
                                                                                
                                                    
                                                                                
                                                                                
                                                    
    Dovecot's NTLM implementation does not correctly check message              
                                                                                
                                                    
    buffer size, which leads to a crash when reading past allocation.           
                                                                                
                                                    
                                                                                
                                                                                
                                                    
CVE-2020-12674                                                                  
                                                                                
                                                    
                                                                                
                                                                                
                                                    
    Dovecot's RPA mechanism implementation accepts zero-length message,         
                                                                                
                                                    
    which leads to assert-crash later on.                                       
                                                                                
                                                    

Reply via email to