This bug was fixed in the package dovecot - 1:2.3.21+dfsg1-2ubuntu6

---------------
dovecot (1:2.3.21+dfsg1-2ubuntu6) noble-security; urgency=medium

  * Patches for CVE-2024-23184, CVE-2024-23185 (LP: #2077324).
    - CVE-2024-23184: A large number of address headers in email resulted
      in excessive CPU usage.
      + d/p/CVE-2024-23184-1-lib-test-llist-Fix-dllist2-test-name.patch
      + d/p/CVE-2024-23184-2-lib-Add-DLLIST2_JOIN.patch
      + 
d/p/CVE-2024-23184-3-lib-mail-test-imap-envelope-Use-test_assert_idx-where-pos.patch
      + 
d/p/CVE-2024-23184-4-lib-mail-Change-message_address-to-be-doubly-linked-list.patch
      + 
d/p/CVE-2024-23184-5-lib-mail-Add-message_address_parse_full-and-struct-messag.patch
      + 
d/p/CVE-2024-23184-6-lib-mail-lib-imap-Optimize-parsing-large-number-of-addres.patch
    - CVE-2024-23185: Abnormally large email headers are now truncated or
      discarded, with a limit of 10MB on a single header and 50MB for all
      the headers of all the parts of an email.
      + 
d/p/CVE-2024-23185-1-lib-mail-message-header-parser-Limit-header-block-to-10MB.patch
      + 
d/p/CVE-2024-23185-2-lib-mail-message-parser-Limit-headers-total-count-to-50MB.patch
    For more information see the following articles:
    CVE-2024-23184 - https://www.openwall.com/lists/oss-security/2024/08/15/3
    CVE-2024-23185 - https://www.openwall.com/lists/oss-security/2024/08/15/4

 -- Mitchell Dzurick <[email protected]>  Mon, 26 Aug 2024
08:52:27 -0700

** Changed in: dovecot (Ubuntu Noble)
       Status: Triaged => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2077324

Title:
  [FFE] CVE-2024-23184/CVE-2024-23185

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/dovecot/+bug/2077324/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to