evolution-data-server: Response injection via STARTTLS in SMTP and POP3
Published Jul 17, 2020
5.9
MEDIUMCVSS 3.1
EPSS 2.81%
Description
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."
Affected products
No data.
Configuration 1
- ≤ 3.36.3
Configuration 2
- 9.0
- 10.0
Configuration 3
- 31
Configuration 4
- 16.04
- 18.04
- 20.04
No data.
Red Hat Enterprise Linux 8
bogofilter-0:1.2.5-2.el8
Fixed · RHSA-2020:4649
Red Hat Enterprise Linux 8
evolution-0:3.28.5-14.el8
Fixed · RHSA-2020:4649
Red Hat Enterprise Linux 8
evolution-data-server-0:3.28.5-14.el8
Fixed · RHSA-2020:4649
Red Hat Enterprise Linux 8
evolution-mapi-0:3.28.3-3.el8
Fixed · RHSA-2020:4649
Red Hat Enterprise Linux 8
openchange-0:2.3-26.el8
Fixed · RHSA-2020:4649
Red Hat Enterprise Linux 5
evolution-data-server
Out of support scope
Red Hat Enterprise Linux 6
evolution-data-server
Out of support scope
Red Hat Enterprise Linux 7
evolution-data-server
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | bogofilter-0:1.2.5-2.el8 | Fixed | RHSA-2020:4649 |
| Red Hat Enterprise Linux 8 | evolution-0:3.28.5-14.el8 | Fixed | RHSA-2020:4649 |
| Red Hat Enterprise Linux 8 | evolution-data-server-0:3.28.5-14.el8 | Fixed | RHSA-2020:4649 |
| Red Hat Enterprise Linux 8 | evolution-mapi-0:3.28.3-3.el8 | Fixed | RHSA-2020:4649 |
| Red Hat Enterprise Linux 8 | openchange-0:2.3-26.el8 | Fixed | RHSA-2020:4649 |
| Red Hat Enterprise Linux 5 | evolution-data-server | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | evolution-data-server | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | evolution-data-server | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- https://access.redhat.com/security/cve/CVE-2020-14928 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1857470 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1173910 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-7064 Advisory
- https://gitlab.gnome.org/GNOME//evolution-data-server/commit/ba82be72cfd427b5d72ff21f929b3a6d8529c4df x_refsource_CONFIRMPatchThird Party Advisory
- https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/f404f33fb01b23903c2bbb16791c7907e457fbac x_refsource_CONFIRMPatchThird Party Advisory
- https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/226 x_refsource_MISCExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00012.html x_refsource_CONFIRMMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMBEZWA22EAYAZQWUX4KPEBER726KSIG/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-14928
- https://security-tracker.debian.org/tracker/DLA-2281-1 x_refsource_CONFIRMThird Party Advisory
- https://security-tracker.debian.org/tracker/DSA-4725-1 x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4429-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-14928
- https://www.debian.org/security/2020/dsa-4725 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.