MGASA-2021-0557

Source
https://advisories.mageia.org/MGASA-2021-0557.html
Import Source
https://advisories.mageia.org/MGASA-2021-0557.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0557
Related
Published
2021-12-19T12:26:08Z
Modified
2021-12-19T11:47:51Z
Summary
Updated dovecot packages fix security vulnerabilities
Details

Updated dovecot packages fix security vulnerabilities:

The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension (CVE-2020-28200).

Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver (CVE-2021-29157).

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address (CVE-2021-33515).

References
Credits

Affected packages