Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 797349 (CVE-2021-29157, CVE-2021-33515) - <net-mail/dovecot-2.3.14.1: Multiple vulnerabilities (CVE-2021-{29157,33515})
Summary: <net-mail/dovecot-2.3.14.1: Multiple vulnerabilities (CVE-2021-{29157,33515})
Status: RESOLVED FIXED
Alias: CVE-2021-29157, CVE-2021-33515
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-06-21 11:27 UTC by Sam James
Modified: 2021-07-18 03:47 UTC (History)
2 users (show)

See Also:
Package list:
net-mail/dovecot-2.3.14.1-r1
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-21 11:27:38 UTC
* CVE-2021-29157

Description:
"Dovecot does not correctly escape kid and azp fields in
JWT tokens. This may be used to supply attacker controlled keys to
validate tokens, if attacker has local access."

* CVE-2021-33515

Description:
"On-path attacker could have injected plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the client."


----
Please bump to 2.3.14.1 and 2.3.15. Thanks!
Comment 1 Larry the Git Cow gentoo-dev 2021-06-21 13:40:29 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e240bf58ed54e64da0a1b7eae61a2b0d5ffd2c3c

commit e240bf58ed54e64da0a1b7eae61a2b0d5ffd2c3c
Author:     Eray Aslan <eras@gentoo.org>
AuthorDate: 2021-06-21 13:40:10 +0000
Commit:     Eray Aslan <eras@gentoo.org>
CommitDate: 2021-06-21 13:40:10 +0000

    net-mail/dovecot: security bump to 2.3.14.1
    
    Bug: https://bugs.gentoo.org/797349
    Package-Manager: Portage-3.0.20, Repoman-3.0.3
    Signed-off-by: Eray Aslan <eras@gentoo.org>

 net-mail/dovecot/Manifest                |   1 +
 net-mail/dovecot/dovecot-2.3.14.1.ebuild | 293 +++++++++++++++++++++++++++++++
 2 files changed, 294 insertions(+)
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-21 14:14:44 UTC
Thanks eras!
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-21 19:04:16 UTC
x86 done
Comment 4 Agostino Sarubbo gentoo-dev 2021-06-22 06:47:25 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2021-06-22 06:47:51 UTC
ppc stable
Comment 6 Agostino Sarubbo gentoo-dev 2021-06-22 06:48:43 UTC
ppc64 stable
Comment 7 NATTkA bot gentoo-dev 2021-06-22 20:56:20 UTC Comment hidden (obsolete)
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-07-17 04:59:41 UTC
arm done

all arches done
Comment 9 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-07-17 05:09:40 UTC
Please cleanup, thanks!
Comment 10 Larry the Git Cow gentoo-dev 2021-07-17 13:01:14 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c7831824c64115adf396d7383272a078d7273633

commit c7831824c64115adf396d7383272a078d7273633
Author:     Eray Aslan <eras@gentoo.org>
AuthorDate: 2021-07-17 13:00:54 +0000
Commit:     Eray Aslan <eras@gentoo.org>
CommitDate: 2021-07-17 13:00:54 +0000

    net-mail/dovecot: cleanup
    
    Bug: https://bugs.gentoo.org/797349
    Package-Manager: Portage-3.0.20, Repoman-3.0.3
    Signed-off-by: Eray Aslan <eras@gentoo.org>

 net-mail/dovecot/Manifest                          |   3 -
 net-mail/dovecot/dovecot-2.3.13-r101.ebuild        | 295 ---------------------
 net-mail/dovecot/dovecot-2.3.14-r1.ebuild          | 294 --------------------
 .../files/dovecot-2.3.13-32-bit-tests-1.patch      |  52 ----
 .../files/dovecot-2.3.13-32-bit-tests-2.patch      |  27 --
 .../dovecot/files/dovecot-unwind-generic.patch     |  15 --
 6 files changed, 686 deletions(-)
Comment 11 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-07-17 16:37:05 UTC
GLSA request filed.
Comment 12 GLSAMaker/CVETool Bot gentoo-dev 2021-07-18 03:47:57 UTC
This issue was resolved and addressed in
 GLSA 202107-41 at https://security.gentoo.org/glsa/202107-41
by GLSA coordinator John Helmert III (ajak).