[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4418-1 dovecot -- dovecot

ID: oval:org.secpod.oval:def:603836Date: (C)2019-04-08   (M)2023-12-20
Class: PATCHFamily: unix




A vulnerability was discovered in the Dovecot email server. When reading FTS or POP3-UIDL headers from the Dovecot index, the input buffer size is not bounds-checked. An attacker with the ability to modify dovecot indexes, can take advantage of this flaw for privilege escalation or the execution of arbitrary code with the permissions of the dovecot user. Only installations using the FTS or pop3 migration plugins are affected.

Platform:
Debian 9.x
Product:
dovecot-pgsql
dovecot-mysql
dovecot-sieve
dovecot-core
dovecot-ldap
dovecot-solr
dovecot-sqlite
dovecot-dbg
dovecot-pop3d
dovecot-imapd
dovecot-managesieved
dovecot-lucene
dovecot-gssapi
dovecot-dev
dovecot-lmtpd
Reference:
DSA-4418-1
CVE-2019-7524
CVE    1
CVE-2019-7524
CPE    5
cpe:/o:debian:debian_linux:9.0
cpe:/a:dovecot:dovecot-core
cpe:/o:debian:debian_linux:9.x
cpe:/a:dovecot:dovecot-dev
...

© SecPod Technologies