Описание
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
A flaw was found in dovecot. An attacker can use the way dovecot handles RPA (Remote Passphrase Authentication) to crash the authentication process repeatedly preventing login. The highest threat from this vulnerability is to system availability.
Меры по смягчению последствий
Upstream suggests that this flaw can be mitigated by disabling RPA (Remote Passphrase Authentication). RPA can be disabled by using the configuration parameter "auth_mechanisms". More details available at: https://doc.dovecot.org/configuration_manual/authentication/authentication_mechanisms/
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | dovecot | Not affected | ||
Red Hat Enterprise Linux 6 | dovecot | Not affected | ||
Red Hat Enterprise Linux 7 | dovecot | Fixed | RHSA-2020:3617 | 03.09.2020 |
Red Hat Enterprise Linux 8 | dovecot | Fixed | RHSA-2020:3713 | 10.09.2020 |
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | dovecot | Fixed | RHSA-2020:3735 | 14.09.2020 |
Red Hat Enterprise Linux 8.1 Extended Update Support | dovecot | Fixed | RHSA-2020:3736 | 14.09.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
In Dovecot before 2.3.11.3, sending a specially formatted RPA request ...
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
Уязвимость почтового сервера Dovecot, связанная с некорректной проверкой входных данных, позволяющая нарушителю привести к сбою в работе службы аутентификации
EPSS
7.5 High
CVSS3