CVE-2019-7524: Buffer Overflow
Published Mar 28, 2019
·Updated
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.
Affected Software
13 affected componentsFixes available
redhat/dovecot<2.3.5.1
2.3.5.1
redhat/dovecot<2.2.36.3
2.2.36.3
Dovecot dovecot<2.2.36.3
Dovecot dovecot>=2.3.0<2.3.5.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
openSUSE Leap=15.0
openSUSE Leap=42.3
debian/dovecot
1:2.3.13+dfsg1-2+deb11u11:2.3.13+dfsg1-2+deb11u21:2.3.19.1+dfsg1-2.1+deb12u11:2.4.1+dfsg1-6+deb13u21:2.4.1+dfsg1-6+deb13u11:2.4.2+dfsg1-3
Event History
Mar 28, 2019
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverity
Feb 23, 2026
Data Sourced
via Ubuntu·05:02 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:02 PM
DescriptionAffected Software
Data Sourced
via Launchpad·05:02 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-7524.
2
What is the severity of CVE-2019-7524?
The severity of CVE-2019-7524 is high.
3
How does CVE-2019-7524 impact Dovecot?
CVE-2019-7524 allows a local attacker to cause a buffer overflow in the indexer-worker process of Dovecot, which can be used to elevate to root.
4
Which versions of Dovecot are affected by CVE-2019-7524?
Dovecot versions before 2.2.36.3 and 2.3.x before 2.3.5.1 are affected by CVE-2019-7524.
5
How can I fix the vulnerability in my Dovecot installation?
To fix the vulnerability, you should update Dovecot to version 2.2.36.3 or 2.3.5.1.