Bug 33466 - Dovecot security issues - CVE-2024-2318[4-5]
Summary: Dovecot security issues - CVE-2024-2318[4-5]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
: 33476 (view as bug list)
Depends on:
Blocks:
 
Reported: 2024-08-14 18:12 CEST by Stig-Ørjan Smelror
Modified: 2024-08-19 12:44 CEST (History)
5 users (show)

See Also:
Source RPM: dovecot
CVE: CVE-2024-23184, CVE-2024-23185
Status comment:


Attachments

Description Stig-Ørjan Smelror 2024-08-14 18:12:07 CEST
Upstream have released version 2.3.21.1 to fix these issues.

https://dovecot.org/mailman3/hyperkitty/list/dovecot-news@dovecot.org/thread/2CSVL56LFPAXVLWMGXEIWZL736PSYHP5/
Comment 1 Stig-Ørjan Smelror 2024-08-14 21:22:21 CEST
Advisory
========

Dovecot has been updated to fix two security issues.

- CVE-2024-23184: A large number of address headers in email resulted
  in excessive CPU usage.
- CVE-2024-23185: Abnormally large email headers are now truncated or
  discarded, with a limit of 10MB on a single header and 50MB for all
  the headers of all the parts of an email.

References
==========

https://dovecot.org/mailman3/hyperkitty/list/dovecot-news@dovecot.org/thread/2CSVL56LFPAXVLWMGXEIWZL736PSYHP5/

Files
=====

dovecot-plugins-sqlite-2.3.21.1-1.mga9
dovecot-plugins-pgsql-2.3.21.1-1.mga9
dovecot-plugins-gssapi-2.3.21.1-1.mga9
dovecot-plugins-mysql-2.3.21.1-1.mga9
dovecot-plugins-ldap-2.3.21.1-1.mga9
dovecot-pigeonhole-devel-2.3.21.1-1.mga9
dovecot-devel-2.3.21.1-1.mga9
dovecot-pigeonhole-2.3.21.1-1.mga9
dovecot-2.3.21.1-1.mga9

from dovecot-2.3.21.1-1.mga9.src.rpm

CVE: (none) => CVE-2024-23184, CVE-2024-23185

Stig-Ørjan Smelror 2024-08-15 05:39:40 CEST

Assignee: smelror => qa-bugs

Comment 2 Herman Viaene 2024-08-15 13:26:41 CEST
No references to wiki or buglist of previous updates shown. Rather essential to me.

CC: (none) => herman.viaene

Comment 3 Herman Viaene 2024-08-15 13:53:26 CEST
MGA9-64 Plasma Wayland on HP-Pavillion.
No installation issues.
Ref bug 13355 for testing
# systemctl start dovecot
# systemctl -l status dovecot
● dovecot.service - Dovecot IMAP/POP3 email server
     Loaded: loaded (/usr/lib/systemd/system/dovecot.service; disabled; preset: disabled)
     Active: active (running) since Thu 2024-08-15 13:43:03 CEST; 24s ago
       Docs: man:dovecot(1)
             https://doc.dovecot.org/
   Main PID: 53181 (dovecot)
     Status: "v2.3.21.1 (d492236fa0) running"
      Tasks: 4 (limit: 4473)
     Memory: 3.6M
        CPU: 159ms
     CGroup: /system.slice/dovecot.service
             ├─53181 /usr/sbin/dovecot -F
             ├─53184 dovecot/anvil
             ├─53185 dovecot/log
             └─53186 dovecot/config

Aug 15 13:43:03 mach4.hviaene.thuis systemd[1]: Starting dovecot.service...
Aug 15 13:43:03 mach4.hviaene.thuis dovecot[53181]: master: Dovecot v2.3.21.1 (d492236fa0) starting up for im>
Aug 15 13:43:03 mach4.hviaene.thuis systemd[1]: Started dovecot.service.

Then, after opeing ports 143 and 110 in firewall.
$ telnet localhost 143
Trying ::1...
telnet: connect to address ::1: Connection refused
Trying 127.0.0.1...
Connected to localhost (127.0.0.1).
Escape character is '^]'.
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN] Dovecot ready.

Connection closed by foreign host.

$ telnet localhost 110
Trying ::1...
telnet: connect to address ::1: Connection refused
Trying 127.0.0.1...
Connected to localhost (127.0.0.1).
Escape character is '^]'.
+OK Dovecot ready.
 Looks good AFAICS.

Whiteboard: (none) => MGA9-64-OK

PC LX 2024-08-15 21:39:09 CEST

CC: (none) => mageia

Comment 4 Thomas Andrews 2024-08-16 02:35:12 CEST
Validating.

CC: (none) => andrewsfarm

Thomas Andrews 2024-08-16 02:36:39 CEST

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

katnatek 2024-08-16 02:52:54 CEST

Keywords: (none) => advisory
Source RPM: (none) => dovecot

Comment 5 Mageia Robot 2024-08-17 18:56:34 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0280.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 6 Stig-Ørjan Smelror 2024-08-19 12:44:58 CEST
*** Bug 33476 has been marked as a duplicate of this bug. ***

CC: (none) => mageia


Note You need to log in before you can comment on or make changes to this bug.