DSA-4825-1 dovecot -- dovecotID: oval:org.secpod.oval:def:605381 | Date: (C)2021-01-05 (M)2023-12-20 |
Class: PATCH | Family: unix |
Several vulnerabilities have been discovered in the Dovecot email server. CVE-2020-24386 When imap hibernation is active, an attacker can cause Dovecot to discover file system directory structures and access other users" emails via specially crafted commands. CVE-2020-25275 Innokentii Sennovskiy reported that the mail delivery and parsing in Dovecot can crash when the 10000th MIME part is message/rfc822 . This flaw was introduced by earlier changes addressing CVE-2020-12100.
Product: |
dovecot-auth-lua |
dovecot-pgsql |
dovecot-mysql |
dovecot-sieve |
dovecot-core |
dovecot-ldap |
dovecot-sqlite |
dovecot-dev |
dovecot-pop3d |
dovecot-imapd |
dovecot-managesieved |
dovecot-lucene |
dovecot-gssapi |
dovecot-solr |
dovecot-submissiond |
dovecot-lmtpd |