CVE-2020-12100
published 2020-08-12CVE-2020-12100: In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.21%
91.6th percentile
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | dovecot | < dovecot 1:2.3.11.3+dfsg1-1 (bookworm) | dovecot 1:2.3.11.3+dfsg1-1 (bookworm) |
| dovecot | dovecot | < 2.3.11.3 | 2.3.11.3 |
| dovecot | dovecot | >= 0 < 1:2.3.11.3+dfsg1-1 | 1:2.3.11.3+dfsg1-1 |
| dovecot | dovecot | >= 0 < 1:2.3.11.3+dfsg1-1 | 1:2.3.11.3+dfsg1-1 |
| dovecot | dovecot | >= 0 < 1:2.3.11.3+dfsg1-1 | 1:2.3.11.3+dfsg1-1 |
| dovecot | dovecot | >= 0 < 1:2.3.11.3+dfsg1-1 | 1:2.3.11.3+dfsg1-1 |
| dovecot | dovecot | >= 0 < 1:2.2.22-1ubuntu2.13 | 1:2.2.22-1ubuntu2.13 |
| dovecot | dovecot | >= 0 < 1:2.2.33.2-1ubuntu4.6 | 1:2.2.33.2-1ubuntu4.6 |
| dovecot | dovecot | >= 0 < 1:2.3.7.2-1ubuntu3.2 | 1:2.3.7.2-1ubuntu3.2 |
| dovecot | dovecot | >= 0 < 1:2.2.9-1ubuntu2.6+esm3 | 1:2.2.9-1ubuntu2.6+esm3 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pq8h-22gg-vpmw: In Dovecot before 2
ghsa_unreviewed·2022-05-24
CVE-2020-12100 [MEDIUM] CWE-674 GHSA-pq8h-22gg-vpmw: In Dovecot before 2
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
OSV
dovecot vulnerabilities
osv·2020-08-17·CVSS 7.5
CVE-2020-12100 [HIGH] dovecot vulnerabilities
dovecot vulnerabilities
USN-4456-1 fixed several vulnerabilities in Dovecot. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Dovecot incorrectly handled deeply nested MIME
parts. A remote attacker could possibly use this issue to cause Dovecot to
consume resources, resulting in a denial of service. (CVE-2020-12100)
It was discovered that Dovecot incorrectly handled memory when using NTLM.
A remote attacker could possibly use this issue to cause Dovecot to crash,
resulting in a denial of service. (CVE-2020-12673)
It was discovered that the Dovecot RPA mechanism incorrectly handled
zero-length messages. A remote attacker could possibly use this issue to
cause Dovecot to crash, resulting in a denial of service. (CVE-20
OSV
dovecot vulnerabilities
osv·2020-08-12·CVSS 7.5
CVE-2020-12100 [HIGH] dovecot vulnerabilities
dovecot vulnerabilities
It was discovered that Dovecot incorrectly handled deeply nested MIME
parts. A remote attacker could possibly use this issue to cause Dovecot to
consume resources, resulting in a denial of service. (CVE-2020-12100)
It was discovered that Dovecot incorrectly handled memory when using NTLM.
A remote attacker could possibly use this issue to cause Dovecot to crash,
resulting in a denial of service. (CVE-2020-12673)
It was discovered that the Dovecot RPA mechanism incorrectly handled
zero-length messages. A remote attacker could possibly use this issue to
cause Dovecot to crash, resulting in a denial of service. (CVE-2020-12674)
OSV
CVE-2020-12100: In Dovecot before 2
osv·2020-08-12·CVSS 7.5
CVE-2020-12100 [HIGH] CVE-2020-12100: In Dovecot before 2
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2020-08-17·CVSS 7.5
CVE-2020-12100 [HIGH] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
USN-4456-1 fixed several vulnerabilities in Dovecot. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Dovecot incorrectly handled deeply nested MIME
parts. A remote attacker could possibly use this issue to cause Dovecot to
consume resources, resulting in a denial of service. (CVE-2020-12100)
It was discovered that Dovecot incorrectly handled memory when using NTLM.
A remote attacker could possibly use this issue to cause Dovecot to crash,
resulting in a denial of service. (CVE-2020-12673)
It was discovered that the Dovecot RPA mechanism incorrectly handled
zero-length messages. A remote attacker could possibly use this issue to
c
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2020-08-12·CVSS 7.5
CVE-2020-12100 [HIGH] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
It was discovered that Dovecot incorrectly handled deeply nested MIME
parts. A remote attacker could possibly use this issue to cause Dovecot to
consume resources, resulting in a denial of service. (CVE-2020-12100)
It was discovered that Dovecot incorrectly handled memory when using NTLM.
A remote attacker could possibly use this issue to cause Dovecot to crash,
resulting in a denial of service. (CVE-2020-12673)
It was discovered that the Dovecot RPA mechanism incorrectly handled
zero-length messages. A remote attacker could possibly use this issue to
cause Dovecot to crash, resulting in a denial of service. (CVE-2020-12674)
Instructions: In general, a standard system update will make all the necess
Red Hat
dovecot: Resource exhaustion via deeply nested MIME parts
vendor_redhat·2020-08-12·CVSS 7.5
CVE-2020-12100 [HIGH] CWE-674 dovecot: Resource exhaustion via deeply nested MIME parts
dovecot: Resource exhaustion via deeply nested MIME parts
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
A flaw was found in dovecot. A remote attacker could cause a denial of service by repeatedly sending emails containing MIME parts containing malicious content of which dovecot will attempt to parse. The highest threat from this vulnerability is to system availability.
Mitigation: Upstream suggests that this flaw can be mitigated by limiting MIME structures in MTA
Package: dovecot (Red Hat Enterprise Linux 5) - Not affected
Package: dovecot (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2020-12100: dovecot - In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda ...
vendor_debian·2020·CVSS 7.5
CVE-2020-12100 [HIGH] CVE-2020-12100: dovecot - In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda ...
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
Scope: local
bookworm: resolved (fixed in 1:2.3.11.3+dfsg1-1)
bullseye: resolved (fixed in 1:2.3.11.3+dfsg1-1)
forky: resolved (fixed in 1:2.3.11.3+dfsg1-1)
sid: resolved (fixed in 1:2.3.11.3+dfsg1-1)
trixie: resolved (fixed in 1:2.3.11.3+dfsg1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts [fedora-all]
bugzilla·2020-08-13·CVSS 7.5
CVE-2020-12100 [HIGH] CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts [fedora-all]
CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts
bugzilla·2020-08-05·CVSS 7.5
CVE-2020-12100 [HIGH] CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts
CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts
As per upstream:
Vulnerability Details:
Receiving mail with deeply nested MIME parts leads to resource exhaustion as Dovecot attempts to parse it.
Risk:
Malicious actor can cause denial of service to mail delivery by repeatedly sending mails with bad content.
Discussion:
Created attachment 1710593
CVE-2020-12100 patch from upstream
---
Mitigation:
Upstream suggests that this flaw can be mitigated by limiting MIME structures in MTA
---
Acknowledgments:
Name: the Dovecot project
---
External References:
https://dovecot.org/pipermail/dovecot-news/2020-August/000441.html
---
Created dovecot tracking bugs for this issue:
Affects: fedora-all [bug 1868539]
---
This issue has been addressed in the following
http://seclists.org/fulldisclosure/2021/Jan/18http://www.openwall.com/lists/oss-security/2020/08/12/1http://www.openwall.com/lists/oss-security/2021/01/04/3https://dovecot.org/securityhttps://lists.debian.org/debian-lts-announce/2020/08/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4AAX2MJEULPVSRZOBX3PNPFSYP4FM4TT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EYZU6CHA3VMYYAUCMHSCCQKJEVEIKPQ2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XKKAL3OMG76ZZ7CIEMQP2K6KCTD2RAKE/https://security.gentoo.org/glsa/202009-02https://usn.ubuntu.com/4456-1/https://usn.ubuntu.com/4456-2/https://www.debian.org/security/2020/dsa-4745http://seclists.org/fulldisclosure/2021/Jan/18http://www.openwall.com/lists/oss-security/2020/08/12/1http://www.openwall.com/lists/oss-security/2021/01/04/3https://dovecot.org/securityhttps://lists.debian.org/debian-lts-announce/2020/08/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4AAX2MJEULPVSRZOBX3PNPFSYP4FM4TT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EYZU6CHA3VMYYAUCMHSCCQKJEVEIKPQ2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XKKAL3OMG76ZZ7CIEMQP2K6KCTD2RAKE/https://security.gentoo.org/glsa/202009-02https://usn.ubuntu.com/4456-1/https://usn.ubuntu.com/4456-2/https://www.debian.org/security/2020/dsa-4745
2020-08-12
Published