[Apollo] Advisories Statistics light light Login

RLSA-2024:6973

Security Mirrored from RHSA-2024:6973
Issued at: 2024-09-30
Updated at: 2024-09-30

Synopsis

Moderate: dovecot security update



Description

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.

Security Fix(es):

* dovecot: using a large number of address headers may trigger a denial of service (CVE-2024-23184)

* dovecot: very large headers can cause resource exhaustion when parsing message (CVE-2024-23185)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 aarch64 Rocky Linux 8 x86_64

Fixes

2305909 2305910

CVEs

CVE-2024-23184 CVE-2024-23185

Affected packages

Rocky Linux 8 aarch64 - AppStream

dovecot-1:2.3.16-6.el8_10.aarch64.rpm dovecot-1:2.3.16-6.el8_10.src.rpm dovecot-debuginfo-1:2.3.16-6.el8_10.aarch64.rpm dovecot-debugsource-1:2.3.16-6.el8_10.aarch64.rpm dovecot-mysql-1:2.3.16-6.el8_10.aarch64.rpm dovecot-mysql-debuginfo-1:2.3.16-6.el8_10.aarch64.rpm dovecot-pgsql-1:2.3.16-6.el8_10.aarch64.rpm dovecot-pgsql-debuginfo-1:2.3.16-6.el8_10.aarch64.rpm dovecot-pigeonhole-1:2.3.16-6.el8_10.aarch64.rpm dovecot-pigeonhole-debuginfo-1:2.3.16-6.el8_10.aarch64.rpm

Rocky Linux 8 x86_64 - PowerTools

dovecot-1:2.3.16-6.el8_10.i686.rpm dovecot-debuginfo-1:2.3.16-6.el8_10.i686.rpm dovecot-debugsource-1:2.3.16-6.el8_10.i686.rpm dovecot-devel-1:2.3.16-6.el8_10.i686.rpm dovecot-devel-1:2.3.16-6.el8_10.x86_64.rpm

Rocky Linux 8 x86_64 - AppStream

dovecot-1:2.3.16-6.el8_10.src.rpm dovecot-1:2.3.16-6.el8_10.x86_64.rpm dovecot-debuginfo-1:2.3.16-6.el8_10.x86_64.rpm dovecot-debugsource-1:2.3.16-6.el8_10.x86_64.rpm dovecot-mysql-1:2.3.16-6.el8_10.x86_64.rpm dovecot-mysql-debuginfo-1:2.3.16-6.el8_10.x86_64.rpm dovecot-pgsql-1:2.3.16-6.el8_10.x86_64.rpm dovecot-pgsql-debuginfo-1:2.3.16-6.el8_10.x86_64.rpm dovecot-pigeonhole-1:2.3.16-6.el8_10.x86_64.rpm dovecot-pigeonhole-debuginfo-1:2.3.16-6.el8_10.x86_64.rpm

Rocky Linux 8 aarch64 - PowerTools

dovecot-devel-1:2.3.16-6.el8_10.aarch64.rpm