ELA-1175-1 dovecot security update

Denial of Service (DoS) vulnerability

2024-09-07
Packagedovecot
Version1:2.2.27-3+deb9u8 (stretch), 1:2.3.4.1-5+deb10u8 (buster)
Related CVEs CVE-2024-23185


A Denial of Service (DoS) vulnerability was discovered in the IMAP implementation of the Dovecot mail server: Very large headers could cause resource exhaustion when parsing message.



For Debian 10 buster, these problems have been fixed in version 1:2.3.4.1-5+deb10u8.

For Debian 9 stretch, these problems have been fixed in version 1:2.2.27-3+deb9u8.

We recommend that you upgrade your dovecot packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.