Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2020:3735 - Security Advisory
Issued:
2020-09-14
Updated:
2020-09-14

RHSA-2020:3735 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: dovecot security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for dovecot is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.

Security Fix(es):

  • dovecot: Resource exhaustion via deeply nested MIME parts (CVE-2020-12100)
  • dovecot: Out of bound reads in dovecot NTLM implementation (CVE-2020-12673)
  • dovecot: Crash due to assert in RPA implementation (CVE-2020-12674)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.0 x86_64

Fixes

  • BZ - 1866309 - CVE-2020-12100 dovecot: Resource exhaustion via deeply nested MIME parts
  • BZ - 1866313 - CVE-2020-12673 dovecot: Out of bound reads in dovecot NTLM implementation
  • BZ - 1866317 - CVE-2020-12674 dovecot: Crash due to assert in RPA implementation

CVEs

  • CVE-2020-12100
  • CVE-2020-12673
  • CVE-2020-12674

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.0

SRPM
dovecot-2.2.36-5.el8_0.3.src.rpm SHA-256: 57d9a0f11fe9021e9b0bc21626c988f3efa4a96c526b235ef38f211a5993f502
ppc64le
dovecot-2.2.36-5.el8_0.3.ppc64le.rpm SHA-256: c5351d394ec9ee0a731bc671899355860eb2e9bc1a56789b5bf217afa881a94a
dovecot-debuginfo-2.2.36-5.el8_0.3.ppc64le.rpm SHA-256: 7be5fd01acda1b1ad25cee50737075ca7a643df1fd1231f4f3ff8816a101126d
dovecot-debugsource-2.2.36-5.el8_0.3.ppc64le.rpm SHA-256: b646f01d575375fa686051097e52f9f29365e54769e7c8cc4e28b61311e0bd36
dovecot-mysql-2.2.36-5.el8_0.3.ppc64le.rpm SHA-256: 640f66b0cf024dbeef204647c236836c751a2d9de0d302e00a57384472d08696
dovecot-mysql-debuginfo-2.2.36-5.el8_0.3.ppc64le.rpm SHA-256: f5cd93394755e8c9bb8be459dc473e433d490a97de7b5a4f6713915799d87569
dovecot-pgsql-2.2.36-5.el8_0.3.ppc64le.rpm SHA-256: 2c8d3dc4f3e39acd034b5925d2d8b5135e8a23f3b139c0adc8839bcce2494c7c
dovecot-pgsql-debuginfo-2.2.36-5.el8_0.3.ppc64le.rpm SHA-256: a4cba34edd18cbf3fd9b09e34ac8e5aa2a066b2194203b5decd88d716aca1eec
dovecot-pigeonhole-debuginfo-2.2.36-5.el8_0.3.ppc64le.rpm SHA-256: 4257d41fd8e7f0c93a017d07d73ad98980bb8821abc73e856aa6aa3ed409b90c

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.0

SRPM
dovecot-2.2.36-5.el8_0.3.src.rpm SHA-256: 57d9a0f11fe9021e9b0bc21626c988f3efa4a96c526b235ef38f211a5993f502
x86_64
dovecot-2.2.36-5.el8_0.3.x86_64.rpm SHA-256: cc78b208ba131b0017c39fc02d1c1c4749a79d94d3a9690711309069ea8c87fa
dovecot-debuginfo-2.2.36-5.el8_0.3.x86_64.rpm SHA-256: d7071fe67e9bbbe73f9d5cfd2d5004da0eed4e8d40994d2c7b67256397ebc6af
dovecot-debugsource-2.2.36-5.el8_0.3.x86_64.rpm SHA-256: 6654ec031d790104d4f25621cd71e3d90cb2bffe49255b9f57d6ab372034693a
dovecot-mysql-2.2.36-5.el8_0.3.x86_64.rpm SHA-256: 13b1a383416d6eb6f57e7d19c93dd29e1441295e5388b62efe23afbe3d7a8125
dovecot-mysql-debuginfo-2.2.36-5.el8_0.3.x86_64.rpm SHA-256: 56d6c1c450ac09e45593dcc7fe398f744b15ee95bcac9203bbc203ee227d0018
dovecot-pgsql-2.2.36-5.el8_0.3.x86_64.rpm SHA-256: 38f87506dc5b7f2ad925fb6a65ccd7f5f7df23648f9305d85eb2a959f97f4afd
dovecot-pgsql-debuginfo-2.2.36-5.el8_0.3.x86_64.rpm SHA-256: b817ba4d1eaf7db4bffddcc9cea1c35510ac2f5cb2b5816734e9012652790be2
dovecot-pigeonhole-debuginfo-2.2.36-5.el8_0.3.x86_64.rpm SHA-256: 227ab04fc943c5bc3d9b598de4541c78ce251140eafe1a5fa4560bc5139cba3d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility