Ubuntu Security Update USN-4993-1: Dovecot vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,934
Reaction score
80
Credits
-1,257
Kirin discovered that Dovecot incorrectly escaped kid and azp fields in JWT tokens. A local attacker could possibly use this issue to validate tokens using arbitrary keys. This issue only affected Ubuntu 20.10 and Ubuntu 21.04. (CVE-2021-29157) Fabian Ising and Damian Poddebniak discovered that Dovecot incorrectly handled STARTTLS when using the SMTP submission service. A remote attacker could possibly use this issue to inject plaintext commands before STARTTLS negotiation. (CVE-2021-33515)

Continue reading...
 


Follow Linux.org

Members online


Latest posts

Top