CVE-2020-28200 - log back

CVE-2020-28200 edited at 28 Jun 2021 10:06:03
References
https://dovecot.org/pipermail/dovecot-news/2021-June/000458.html
https://dovecot.org/pipermail/dovecot-news/2021-June/000460.html
+ https://www.openwall.com/lists/oss-security/2021/06/28/3
https://github.com/dovecot/pigeonhole/commit/68505e444f91ebd784d419a8c11f1bc3fda3ceab
CVE-2020-28200 edited at 21 Jun 2021 15:03:38
Description
- A security issue has been found in Dovecot before version 2.3.15 and Pigeonhole before version 0.5.15. The Sieve interpreter is not protected against abusive scripts that claim excessive resource usage, especially scripts using massive amounts of regexps. This means an attacker can cause a denial of service of the mail delivery system by using excessive amount of CPU and/or reaching the lmtp/lda process limits.
+ A security issue has been found in Pigeonhole before version 0.5.15. The Sieve interpreter is not protected against abusive scripts that claim excessive resource usage, especially scripts using massive amounts of regexps. This means an attacker can cause a denial of service of the mail delivery system by using excessive amount of CPU and/or reaching the lmtp/lda process limits.
References
+ https://dovecot.org/pipermail/dovecot-news/2021-June/000458.html
https://dovecot.org/pipermail/dovecot-news/2021-June/000460.html
- https://dovecot.org/pipermail/dovecot-news/2021-June/000458.html
+ https://github.com/dovecot/pigeonhole/commit/68505e444f91ebd784d419a8c11f1bc3fda3ceab
CVE-2020-28200 edited at 21 Jun 2021 14:52:41
Description
- A security issue has been found in Dovecot before version 2.3.15. The Sieve interpreter is not protected against abusive scripts that claim excessive resource usage, especially scripts using massive amounts of regexps. This means an attacker can cause a denial of service of the mail delivery system by using excessive amount of CPU and/or reaching the lmtp/lda process limits.
+ A security issue has been found in Dovecot before version 2.3.15 and Pigeonhole before version 0.5.15. The Sieve interpreter is not protected against abusive scripts that claim excessive resource usage, especially scripts using massive amounts of regexps. This means an attacker can cause a denial of service of the mail delivery system by using excessive amount of CPU and/or reaching the lmtp/lda process limits.
References
https://dovecot.org/pipermail/dovecot-news/2021-June/000460.html
+ https://dovecot.org/pipermail/dovecot-news/2021-June/000458.html
CVE-2020-28200 edited at 21 Jun 2021 14:46:44
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ A security issue has been found in Dovecot before version 2.3.15. The Sieve interpreter is not protected against abusive scripts that claim excessive resource usage, especially scripts using massive amounts of regexps. This means an attacker can cause a denial of service of the mail delivery system by using excessive amount of CPU and/or reaching the lmtp/lda process limits.
References
+ https://dovecot.org/pipermail/dovecot-news/2021-June/000460.html
Notes
+ Workaround
+ ==========
+
+ Disabling the regex sieve extension avoids the worst problems. lmtp_user_concurrency_limit may also be helpful.
CVE-2020-28200 created at 21 Jun 2021 14:43:15