ALAS2-2019-1347


Amazon Linux 2 Security Advisory: ALAS-2019-1347
Advisory Release Date: 2019-11-04 22:10 Pacific
Advisory Updated Date: 2019-11-07 00:27 Pacific
Severity: Important

Issue Overview:

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.(CVE-2019-11500)


Affected Packages:

dovecot


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update dovecot to update your system.

New Packages:
aarch64:
    dovecot-2.2.36-3.amzn2.1.aarch64
    dovecot-pigeonhole-2.2.36-3.amzn2.1.aarch64
    dovecot-pgsql-2.2.36-3.amzn2.1.aarch64
    dovecot-mysql-2.2.36-3.amzn2.1.aarch64
    dovecot-devel-2.2.36-3.amzn2.1.aarch64
    dovecot-debuginfo-2.2.36-3.amzn2.1.aarch64

i686:
    dovecot-2.2.36-3.amzn2.1.i686
    dovecot-pigeonhole-2.2.36-3.amzn2.1.i686
    dovecot-pgsql-2.2.36-3.amzn2.1.i686
    dovecot-mysql-2.2.36-3.amzn2.1.i686
    dovecot-devel-2.2.36-3.amzn2.1.i686
    dovecot-debuginfo-2.2.36-3.amzn2.1.i686

src:
    dovecot-2.2.36-3.amzn2.1.src

x86_64:
    dovecot-2.2.36-3.amzn2.1.x86_64
    dovecot-pigeonhole-2.2.36-3.amzn2.1.x86_64
    dovecot-pgsql-2.2.36-3.amzn2.1.x86_64
    dovecot-mysql-2.2.36-3.amzn2.1.x86_64
    dovecot-devel-2.2.36-3.amzn2.1.x86_64
    dovecot-debuginfo-2.2.36-3.amzn2.1.x86_64