CVE-2011-1929: Input Validation
Dovecot has released version 1.2.17 [1] and 2.0.13 [2] to address a potential crash, and possibly mailbox corruption, when dovecot parsed header names that contained NUL characters. This was due to a pointer possibly pointing past allocated memory. An upstream patch [3] is available.
[1] http://dovecot.org/pipermail/dovecot/2011-May/059086.html [2] http://dovecot.org/pipermail/dovecot/2011-May/059085.html [3] http://hg.dovecot.org/dovecot-1.1/rev/3698dfe0f21c
Other sources
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1929?
CVE-2011-1929 has been assigned a severity rating that indicates it poses a risk of crash or mailbox corruption under certain conditions.
How do I fix CVE-2011-1929?
To fix CVE-2011-1929, update your Dovecot installation to version 1.2.17 or 2.0.13 or later.
Which Dovecot versions are affected by CVE-2011-1929?
CVE-2011-1929 affects Dovecot versions 1.2.0 through 1.2.16 and 2.0.0 through 2.0.12.
What type of vulnerability is CVE-2011-1929?
CVE-2011-1929 is a vulnerability that can lead to application crashes and potentially corrupt user mailboxes.
Are there any known exploits for CVE-2011-1929?
While no specific exploits have been publicized for CVE-2011-1929, the nature of the vulnerability presents a risk in vulnerable systems.