Описание
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
A flaw was found in dovecot. An out-of-bounds read flaw was found in the way dovecot handled NTLM authentication allowing an attacker to crash the dovecot auth process repeatedly preventing login. The highest threat from this vulnerability is to system availability.
Меры по смягчению последствий
Upstream suggests that this flaw can be mitigated by disabling NTLM authentication. NTLM authentication can be disabled by using the configuration parameter "auth_mechanisms". More details available at: https://doc.dovecot.org/configuration_manual/authentication/authentication_mechanisms/
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | dovecot | Not affected | ||
Red Hat Enterprise Linux 6 | dovecot | Not affected | ||
Red Hat Enterprise Linux 7 | dovecot | Fixed | RHSA-2020:3617 | 03.09.2020 |
Red Hat Enterprise Linux 8 | dovecot | Fixed | RHSA-2020:3713 | 10.09.2020 |
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | dovecot | Fixed | RHSA-2020:3735 | 14.09.2020 |
Red Hat Enterprise Linux 8.1 Extended Update Support | dovecot | Fixed | RHSA-2020:3736 | 14.09.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request ...
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
Уязвимость почтового сервера Dovecot, связанная с некорректной проверкой входных данных, позволяющая нарушителю привести к нарушению в работе службы аутентификации
EPSS
7.5 High
CVSS3