Bug 25868

Summary: dovecot possible new security issue CVE-2019-19722
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Stig-Ørjan Smelror <smelror>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: smelror
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: dovecot-2.3.7.2-3.mga8.src.rpm CVE: CVE-2019-19722
Status comment:

Description David Walser 2019-12-13 12:13:25 CET
A security issue has been fixed in Dovecot 2.3.9.1 today (December 13):
https://dovecot.org/pipermail/dovecot-news/2019-December/000426.html
https://dovecot.org/pipermail/dovecot-news/2019-December/000425.html

If only 2.3.9 is affected, then we are not affected.  If older versions are affected, then we are and Mageia 7 is also affected.

The 2.3.9 announcement says a couple of things about push notifications, so it's possible that's where the issue was introduced:
https://dovecot.org/pipermail/dovecot-news/2019-December/000423.html
Comment 1 Stig-Ørjan Smelror 2019-12-13 13:25:30 CET
2.3.9.1 pushed to Cauldron.

Can't find any info if older versions are affected or not.

If wanted, I can push 2.3.9.1 to Mageia 7 to be on the safe side.


Cheers,
Stig

CC: (none) => smelror
Assignee: bugsquad => smelror
CVE: (none) => CVE-2019-19722

Comment 2 David Walser 2019-12-13 14:11:32 CET
I guess we can wait and see what other distros do.

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 3 David Walser 2019-12-13 21:45:07 CET
You'll need to update again to 2.3.9.2 though:
https://www.openwall.com/lists/oss-security/2019/12/13/3
https://dovecot.org/pipermail/dovecot/2019-December/117893.html
Comment 4 David Walser 2019-12-13 21:45:58 CET
One more reference:
https://dovecot.org/pipermail/dovecot/2019-December/117894.html
Comment 5 Stig-Ørjan Smelror 2019-12-13 22:05:47 CET
2.3.9.2 pushed to Cauldron.
Comment 6 David Walser 2020-01-12 17:37:43 CET
Fedora has issued an advisory for this on January 8:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4OZCJ3RBA4WIYGN7SOV4TW2AIHXPZATK/

Still doesn't clearly indicate that older versions are affected though.

Severity: normal => major