Input validation error in Dovecot - CVE-2020-25275
Published: January 4, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing messages with more than 10 000 MIME parts. A remote attacker can send a specially crafted message to the application and perform a denial of service (DoS) attack.
Note, this vulnerability was introduced by the fix for #VU45671.
Affected software
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
openEuler
Fedora
dovecot (Debian package)
dovecot (Red Hat package)
dovecot (Alpine package)
dovecot-core (Ubuntu package)
dovecot
dovecot-help
dovecot-devel
dovecot-debuginfo
dovecot-debugsource
How to mitigate CVE-2020-25275
dovecot (Debian package) - update to 2.3.4.1-5+deb10u5
dovecot (Red Hat package) - update to 2.3.8-9.el8
dovecot (Alpine package) - update to 2.3.13-r0
dovecot-core (Ubuntu package) - addressed in versions 1:2.2.9-1ubuntu2.6+esm4, 1:2.2.22-1ubuntu2.14, 1:2.2.33.2-1ubuntu4.7, 1:2.3.7.2-1ubuntu3.3, 1:2.3.11.3+dfsg1-2ubuntu0.1
dovecot - update to 2.3.10.1-4
dovecot-help - update to 2.3.10.1-4
dovecot-devel - update to 2.3.10.1-4
dovecot-debuginfo - update to 2.3.10.1-4
dovecot-debugsource - update to 2.3.10.1-4
dovecot - addressed in versions 2.3.13-1.fc32, 2.3.13-1.fc33, 2.3.13-2.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in Dovecot
- Arch Linux update for dovecot
- Debian update for dovecot
- Input validation error in dovecot (Alpine package)
- Gentoo update for Dovecot
- Red Hat Enterprise Linux 8 update for dovecot
- Ubuntu update for dovecot
- Ubuntu update for dovecot
- openEuler update for dovecot
- Fedora 32 update for dovecot
- Fedora 33 update for dovecot
- Fedora 32 update for dovecot