Hide Forgot
On-path attacker could inject plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the client. Only the SMTP submission service is affected. Reference : https://dovecot.org/pipermail/dovecot-news/2021-June/000462.html
Created dovecot tracking bugs for this issue: Affects: fedora-all [bug 1974393]
Upstream fix : https://github.com/dovecot/core/commit/321c339756f9b2b98fb7326359d1333adebb5295
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:1950 https://access.redhat.com/errata/RHSA-2022:1950
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-33515