MGASA-2020-0330

Source
https://advisories.mageia.org/MGASA-2020-0330.html
Import Source
https://advisories.mageia.org/MGASA-2020-0330.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0330
Related
Published
2020-08-18T17:41:27Z
Modified
2020-08-18T16:52:04Z
Summary
Updated dovecot packages fix security vulnerability
Details

CVE-2020-12100: Receiving mail with deeply nested MIME parts leads to resource exhaustion as Dovecot attempts to parse it. CVE-2020-12673: Dovecot's NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-12674: Dovecot's RPA mechanism implementation accepts zero-length message, which leads to assert-crash later on.

References
Credits

Affected packages