CVE-2020-12100: Parsing mails with a large number of MIME parts could
have resulted in excessive CPU usage or a crash due to running out of
stack memory.
CVE-2020-12673: Dovecot's NTLM implementation does not correctly check
message buffer size, which leads to reading past allocation which can
lead to crash.
CVE-2020-10967: lmtp/submission: Issuing the RCPT command with an
address that has the empty quoted string as local-part causes the lmtp
service to crash.
CVE-2020-12674: Dovecot's RPA mechanism implementation accepts
zero-length message, which leads to assert-crash later on.
Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:
sudo dnf upgrade --refresh --advisory=FEDORA-2020-d737c57172
Please login to add feedback.
This update has been submitted for testing by mhlavink.
This update's test gating status has been changed to 'ignored'.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'ignored'.
This update has been pushed to testing.
Hmm, appears to have broken GSSAPI authentication. Still testing.
Yep, GSSAPI authentication broken. Reverting to previous dovecot immediately restores it.
Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.
This update can be pushed to stable now if the maintainer wishes
mhlavink edited this update.
New build(s):
Removed build(s):
Karma has been reset.
This update has been submitted for testing by mhlavink.
Works, including gssapi authentication.
This update has been pushed to testing.
This update can be pushed to stable now if the maintainer wishes
can this be pushed to release?
or is there specific add'l testing needed?
This update has been submitted for stable by mhlavink.
This update has been pushed to stable.