CVE-2020-28200
Publication date 21 June 2021
Last updated 11 September 2024
Ubuntu priority
Cvss 3 Severity Score
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
Mitigation
Disabling the regex sieve extension avoids the worst problems. lmtp_user_concurrency_limit may also be helpful.
Status
Package | Ubuntu Release | Status |
---|---|---|
dovecot | 24.04 LTS noble |
Not affected
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal | Ignored | |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Ignored | |
14.04 LTS trusty | Ignored |
Notes
mdeslaur
Per upstream, fixing this is a massive change that cannot be backported to earlier releases. As such, we will not be fixing this issue in older Ubuntu releases. Marking as ignored. For users of earlier releases, we recommend disabling the regex sieve extension.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 4.3 · Medium |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | Low |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |