Amazon Linux 2 Security Advisory: ALAS-2019-1347
Advisory Release Date: 2019-11-04 22:10 Pacific
Advisory Updated Date: 2019-11-07 00:27 Pacific
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.(CVE-2019-11500)
Affected Packages:
dovecot
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update dovecot to update your system.
aarch64:
dovecot-2.2.36-3.amzn2.1.aarch64
dovecot-pigeonhole-2.2.36-3.amzn2.1.aarch64
dovecot-pgsql-2.2.36-3.amzn2.1.aarch64
dovecot-mysql-2.2.36-3.amzn2.1.aarch64
dovecot-devel-2.2.36-3.amzn2.1.aarch64
dovecot-debuginfo-2.2.36-3.amzn2.1.aarch64
i686:
dovecot-2.2.36-3.amzn2.1.i686
dovecot-pigeonhole-2.2.36-3.amzn2.1.i686
dovecot-pgsql-2.2.36-3.amzn2.1.i686
dovecot-mysql-2.2.36-3.amzn2.1.i686
dovecot-devel-2.2.36-3.amzn2.1.i686
dovecot-debuginfo-2.2.36-3.amzn2.1.i686
src:
dovecot-2.2.36-3.amzn2.1.src
x86_64:
dovecot-2.2.36-3.amzn2.1.x86_64
dovecot-pigeonhole-2.2.36-3.amzn2.1.x86_64
dovecot-pgsql-2.2.36-3.amzn2.1.x86_64
dovecot-mysql-2.2.36-3.amzn2.1.x86_64
dovecot-devel-2.2.36-3.amzn2.1.x86_64
dovecot-debuginfo-2.2.36-3.amzn2.1.x86_64