Dovecot version in precise too old to switch off SSLv3 protocol for "poodle" fix
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
dovecot (Ubuntu) |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Lucid |
Won't Fix
|
Undecided
|
Unassigned | ||
Precise |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Trusty |
Fix Released
|
Undecided
|
Unassigned | ||
Utopic |
Fix Released
|
Undecided
|
Unassigned | ||
Vivid |
Fix Released
|
Undecided
|
Marc Deslauriers |
Bug Description
SRU Request:
[Impact]
Dovecot in Precise does not contain the ssl_protocols configuration option that allows disabling SSLv3. Since there are now known weaknesses in SSLv3, it would be preferable to have an option to disable it like on later releases.
It may not be appropriate to default to having SSLv3 disabled yet. As such, this SRU only adds the configuration option, but doesn't enable it.
[Test Case]
1- Configure dovecot
2- Connect with SSLv3 only
3- add "ssl_protocols = !SSLv3" to dovecot configuration file
4- Connect with SSLv3 only
5- Connect with TLS to make sure it still works
Alternatively, the security team QRT script has been modified to test for this. It can be used.
[Regression Potential]
This touches the config file parsing code, and the SSL code. Any regression could result in the configuration file not being parsed correctly, or for some unknown issue with SSL negotiation.
Original description:
The current version of dovecot in Ubuntu 12.04 LTS, Precise Pangolin is 2.0.19
This version is too old to switch off SSLv3 which has been designated insecure as of the recent "poodle" discovery [1].
In dovecot versions 2.1+ the protocol can be switched off, but for older versions the source code would need to be patched [2,3]
I asked the Ubuntu team to either backport a patch to 2.0.19, or package a newer version of dovecot for precise.
[1] https:/
[2] http://
[3] http://<email address hidden>
source package in precise security: dovecot 1:2.0.19-0ubuntu2.1
Related branches
CVE References
information type: | Private Security → Public |
tags: | added: poodle |
Changed in dovecot (Ubuntu): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in dovecot (Ubuntu Vivid): | |
status: | Confirmed → Fix Released |
Changed in dovecot (Ubuntu Utopic): | |
status: | New → Fix Released |
Changed in dovecot (Ubuntu Trusty): | |
status: | New → Fix Released |
Changed in dovecot (Ubuntu Precise): | |
status: | New → Confirmed |
Changed in dovecot (Ubuntu Lucid): | |
status: | New → Confirmed |
Changed in dovecot (Ubuntu Precise): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
information type: | Public Security → Private Security |
information type: | Private Security → Public Security |
description: | updated |
description: | updated |
Changed in dovecot (Ubuntu Precise): | |
status: | Confirmed → In Progress |
tags: |
added: verification-done removed: verification-needed |
Here is the patch from the mailing list([3] in original post)