CVE-2020-24386

NameCVE-2020-24386
DescriptionAn issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2517-1, DSA-4825-1
Debian Bugs979363

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dovecot (PTS)jessie, jessie (lts)1:2.2.13-12~deb8u9fixed
stretch (security)1:2.2.27-3+deb9u7fixed
stretch (lts), stretch1:2.2.27-3+deb9u8fixed
buster, buster (lts)1:2.3.4.1-5+deb10u8fixed
buster (security)1:2.3.4.1-5+deb10u7fixed
bullseye1:2.3.13+dfsg1-2+deb11u1fixed
bullseye (security)1:2.3.13+dfsg1-2+deb11u2fixed
bookworm (security), bookworm1:2.3.19.1+dfsg1-2.1+deb12u1fixed
sid, trixie1:2.3.21.1+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dovecotsourcejessie(not affected)
dovecotsourcestretch1:2.2.27-3+deb9u7DLA-2517-1
dovecotsourcebuster1:2.3.4.1-5+deb10u5DSA-4825-1
dovecotsource(unstable)1:2.3.13+dfsg1-1979363

Notes

https://dovecot.org/pipermail/dovecot-news/2021-January/000450.html
https://github.com/dovecot/core/commit/00df2308b0733e810824545183d73276c416cdd3
https://github.com/dovecot/core/commit/b4a9872b833b7985c7d0e7615f1b7fc812dd4c55
[jessie] - dovecot <not-affected> (Hibernate support added in v2.2.19)

Search for package or bug name: Reporting problems