CVE-2020-25275

Published: 04 January 2021

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

Priority

Medium

Status

Package Release Status
dovecot
Launchpad, Ubuntu, Debian
Upstream
Released (2.3.13)
Ubuntu 21.04 (Hirsute Hippo)
Released (1:2.3.11.3+dfsg1-2ubuntu1)
Ubuntu 20.10 (Groovy Gorilla)
Released (1:2.3.11.3+dfsg1-2ubuntu0.1)
Ubuntu 20.04 LTS (Focal Fossa)
Released (1:2.3.7.2-1ubuntu3.3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (1:2.2.33.2-1ubuntu4.7)
Ubuntu 16.04 LTS (Xenial Xerus)
Released (1:2.2.22-1ubuntu2.14)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (1:2.2.9-1ubuntu2.6+esm4)
Ubuntu 12.04 ESM (Precise Pangolin) Ignored

Notes

AuthorNote
mdeslaur per upstream, Vulnerable version: 2.3.11-2.3.11.3 we backported fix to earlier releases, so they are vulnerable

References