Dovecot: Multiple vulnerabilities — GLSA 202009-02

Multiple vulnerabilities have been found in Dovecot, the worst of which could allow remote attackers to cause a Denial of Service condition.

Affected packages

net-mail/dovecot on all architectures
Affected versions < 2.3.11.3
Unaffected versions >= 2.3.11.3

Background

Dovecot is an open source IMAP and POP3 email server.

Description

It was discovered that Dovecot incorrectly handled deeply nested MIME parts, incorrectly handled memory when using NTLM, and incorrectly handled zero-length messages.

Impact

A remote attacker could send a specially crafted mail or send specially crafted authentication requests possibly resulting in a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All Dovecot users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-mail/dovecot-2.3.11.3"
 

References

Release date
September 06, 2020

Latest revision
September 06, 2020: 1

Severity
normal

Exploitable
remote

Bugzilla entries