SB2020051823 - NULL pointer dereference in dovecot (Alpine package)
Published: May 18, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2020-10957)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing NOOP command. A remote attacker can send a specially crafted NOOP command to submission, submission-login or lmtp service, trigger a NULL pointer dereference and perform a denial of service attack.
PoC command:
``NOOP EE"FY``
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=4188e3f4c8c70ca30f481278b85d52799ade266a
- https://git.alpinelinux.org/aports/commit/?id=63c2cc277e73718a89df156cafffdaaf5bbad6cc
- https://git.alpinelinux.org/aports/commit/?id=e9ada9531d3f3e60456ec07437a2f39f9a196861
- https://git.alpinelinux.org/aports/commit/?id=25fe34656b9e14d6e4e67944f178c6687c95c901
- https://git.alpinelinux.org/aports/commit/?id=2b1449bb52bbd408ea452e0f29312761f669c517