Bug 1800502 (CVE-2020-7957) - CVE-2020-7957 dovecot: specially crafted email can cause mailbox to have permanently unaccessible mail
Summary: CVE-2020-7957 dovecot: specially crafted email can cause mailbox to have perm...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2020-7957
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1800498
TreeView+ depends on / blocked
 
Reported: 2020-02-07 09:42 UTC by Marian Rehak
Modified: 2021-02-16 20:38 UTC (History)
6 users (show)

Fixed In Version: dovecot 2.3.9.3
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-02-17 05:16:48 UTC
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2020-02-07 09:42:40 UTC
Sending specially crafted email can cause mailbox to have permanently unaccessible mail, or the mail can be stuck in delivery.

Comment 1 Huzaifa S. Sidhpurwala 2020-02-17 05:14:32 UTC
External References:

https://dovecot.org/pipermail/dovecot-news/2020-February/000430.html

Comment 2 Huzaifa S. Sidhpurwala 2020-02-17 05:16:48 UTC
This issue is already addressed in Fedora via the following updates:

Fedora-30-testing: http://koji.fedoraproject.org/packages/dovecot/2.3.9.3/1.fc30
Fedora-31-testing: http://koji.fedoraproject.org/packages/dovecot/2.3.9.3/1.fc31

Comment 3 Huzaifa S. Sidhpurwala 2020-02-17 05:32:44 UTC
Upstream commit: https://github.com/dovecot/core/commit/3a55f35c208b5fd3d52c0a6272bd5b8717a2ae54


Note You need to log in before you can comment on or make changes to this bug.