CVE-2020-25275
Published: 04 January 2021
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
Priority
Status
Package | Release | Status |
---|---|---|
dovecot Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.3.13)
|
Ubuntu 21.04 (Hirsute Hippo) |
Released
(1:2.3.11.3+dfsg1-2ubuntu1)
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Released
(1:2.3.11.3+dfsg1-2ubuntu0.1)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Released
(1:2.3.7.2-1ubuntu3.3)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(1:2.2.33.2-1ubuntu4.7)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(1:2.2.22-1ubuntu2.14)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Released
(1:2.2.9-1ubuntu2.6+esm4)
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Ignored
|
Notes
Author | Note |
---|---|
mdeslaur | per upstream, Vulnerable version: 2.3.11-2.3.11.3 we backported fix to earlier releases, so they are vulnerable |