安全公告详情

NS-SA-2022-0057

2022-05-08 20:35:23

简介

moderate: krb5/dovecot security update

严重级别

moderate

主题

An update for krb5/dovecot is now available for NewStart CGSL MAIN 6.02.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

krb5: This package provides debug information for package krb5-devel. Debug information is useful when developing applications that use this package or when debugging this package.
dovecot: This package provides debug information for package dovecot-pigeonhole. Debug information is useful when developing applications that use this package or when debugging this package.


Security Fix(es):
krb5: A flaw was found in krb5. MIT Kerberos 5 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.(CVE-2020-28196)
krb5: bugfix
dovecot: An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).(CVE-2020-24386)
dovecot: Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.(CVE-2020-25275)
dovecot: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.02.80B5.

影响组件

  • krb5
  • dovecot

影响产品

  • CGSL MAIN 6.02

更新包

{"fix":[{"product":"CGSL MAIN 6.02","pkgs":[{"binary":["krb5-devel-debuginfo-1.18.2-8.el8.x86_64.rpm","krb5-server-1.18.2-8.el8.x86_64.rpm","krb5-debuginfo-1.18.2-8.el8.x86_64.rpm","krb5-server-ldap-debuginfo-1.18.2-8.el8.x86_64.rpm","krb5-libs-1.18.2-8.el8.x86_64.rpm","libkadm5-1.18.2-8.el8.x86_64.rpm","krb5-server-ldap-1.18.2-8.el8.x86_64.rpm","krb5-devel-1.18.2-8.el8.x86_64.rpm","krb5-libs-debuginfo-1.18.2-8.el8.x86_64.rpm","libkadm5-debuginfo-1.18.2-8.el8.x86_64.rpm","krb5-pkinit-debuginfo-1.18.2-8.el8.x86_64.rpm","krb5-debugsource-1.18.2-8.el8.x86_64.rpm","krb5-workstation-debuginfo-1.18.2-8.el8.x86_64.rpm","krb5-workstation-1.18.2-8.el8.x86_64.rpm","krb5-pkinit-1.18.2-8.el8.x86_64.rpm","krb5-server-debuginfo-1.18.2-8.el8.x86_64.rpm"],"source":"krb5-1.18.2-8.el8.src.rpm"},{"binary":["dovecot-pigeonhole-debuginfo-2.3.8-9.el8.x86_64.rpm","dovecot-devel-2.3.8-9.el8.x86_64.rpm","dovecot-debuginfo-2.3.8-9.el8.x86_64.rpm","dovecot-pgsql-debuginfo-2.3.8-9.el8.x86_64.rpm","dovecot-mysql-debuginfo-2.3.8-9.el8.x86_64.rpm","dovecot-debugsource-2.3.8-9.el8.x86_64.rpm","dovecot-2.3.8-9.el8.x86_64.rpm","dovecot-pgsql-2.3.8-9.el8.x86_64.rpm","dovecot-mysql-2.3.8-9.el8.x86_64.rpm","dovecot-pigeonhole-2.3.8-9.el8.x86_64.rpm"],"source":"dovecot-2.3.8-9.el8.src.rpm"}]}]}

CVE

参考