Bug 25868 - dovecot possible new security issue CVE-2019-19722
Summary: dovecot possible new security issue CVE-2019-19722
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Stig-Ørjan Smelror
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-12-13 12:13 CET by David Walser
Modified: 2020-01-12 17:37 CET (History)
1 user (show)

See Also:
Source RPM: dovecot-2.3.7.2-3.mga8.src.rpm
CVE: CVE-2019-19722
Status comment:


Attachments

Description David Walser 2019-12-13 12:13:25 CET
A security issue has been fixed in Dovecot 2.3.9.1 today (December 13):
https://dovecot.org/pipermail/dovecot-news/2019-December/000426.html
https://dovecot.org/pipermail/dovecot-news/2019-December/000425.html

If only 2.3.9 is affected, then we are not affected.  If older versions are affected, then we are and Mageia 7 is also affected.

The 2.3.9 announcement says a couple of things about push notifications, so it's possible that's where the issue was introduced:
https://dovecot.org/pipermail/dovecot-news/2019-December/000423.html
Comment 1 Stig-Ørjan Smelror 2019-12-13 13:25:30 CET
2.3.9.1 pushed to Cauldron.

Can't find any info if older versions are affected or not.

If wanted, I can push 2.3.9.1 to Mageia 7 to be on the safe side.


Cheers,
Stig

CC: (none) => smelror
Assignee: bugsquad => smelror
CVE: (none) => CVE-2019-19722

Comment 2 David Walser 2019-12-13 14:11:32 CET
I guess we can wait and see what other distros do.

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 3 David Walser 2019-12-13 21:45:07 CET
You'll need to update again to 2.3.9.2 though:
https://www.openwall.com/lists/oss-security/2019/12/13/3
https://dovecot.org/pipermail/dovecot/2019-December/117893.html
Comment 4 David Walser 2019-12-13 21:45:58 CET
One more reference:
https://dovecot.org/pipermail/dovecot/2019-December/117894.html
Comment 5 Stig-Ørjan Smelror 2019-12-13 22:05:47 CET
2.3.9.2 pushed to Cauldron.
Comment 6 David Walser 2020-01-12 17:37:43 CET
Fedora has issued an advisory for this on January 8:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4OZCJ3RBA4WIYGN7SOV4TW2AIHXPZATK/

Still doesn't clearly indicate that older versions are affected though.

Severity: normal => major


Note You need to log in before you can comment on or make changes to this bug.