Commit b853ea3b authored by Lev Lamberov's avatar Lev Lamberov

[SECURITY] [DSA 4418-1] dovecot security update

parent 53fa8ab8
<define-tag pagetitle>DSA-4418-1 dovecot</define-tag>
<define-tag report_date>2019-3-28</define-tag>
<define-tag secrefs>CVE-2019-7524</define-tag>
<define-tag packages>dovecot</define-tag>
<define-tag isvulnerable>yes</define-tag>
<define-tag fixed>yes</define-tag>
<define-tag fixed-section>no</define-tag>
#use wml::debian::security
</dl>
<define-tag description>security update</define-tag>
<define-tag moreinfo>
<p>A vulnerability was discovered in the Dovecot email server. When reading
FTS or POP3-UIDL headers from the Dovecot index, the input buffer size
is not bounds-checked. An attacker with the ability to modify dovecot
indexes, can take advantage of this flaw for privilege escalation or the
execution of arbitrary code with the permissions of the dovecot user.
Only installations using the FTS or pop3 migration plugins are affected.</p>
<p>For the stable distribution (stretch), this problem has been fixed in
version 1:2.2.27-3+deb9u4.</p>
<p>We recommend that you upgrade your dovecot packages.</p>
<p>For the detailed security status of dovecot please refer to its
security tracker page at:
<a href="https://security-tracker.debian.org/tracker/dovecot">\
https://security-tracker.debian.org/tracker/dovecot</a></p>
</define-tag>
# do not modify the following line
#include "$(ENGLISHDIR)/security/2019/dsa-4418.data"
# $Id: $
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment