[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4418-1 dovecot -- dovecot

ID: oval:org.secpod.oval:def:70625Date: (C)2021-04-01   (M)2022-10-10
Class: PATCHFamily: unix




A vulnerability was discovered in the Dovecot email server. When reading FTS or POP3-UIDL headers from the Dovecot index, the input buffer size is not bounds-checked. An attacker with the ability to modify dovecot indexes, can take advantage of this flaw for privilege escalation or the execution of arbitrary code with the permissions of the dovecot user. Only installations using the FTS or pop3 migration plugins are affected.

Platform:
Linux Mint 3
Product:
dovecot-dev
dovecot-core
Reference:
DSA-4418-1
CVE-2019-7524
CVE    1
CVE-2019-7524

© SecPod Technologies