First published: Wed Mar 10 2010(Updated: )
Dovecot upstream has released latest v1.2.11 version: [1] <a href="http://www.dovecot.org/list/dovecot-news/2010-March/000152.html">http://www.dovecot.org/list/dovecot-news/2010-March/000152.html</a> addressing one denial of service issue (from upstream announcement): "mbox users really should upgrade, because by sending a message with a huge header you could basically cause a DoS (this problem exists only with v1.2.x, not with v1.0 or v1.1)." References: [2] <a href="http://dovecot.org/pipermail/dovecot/2010-February/047190.html">http://dovecot.org/pipermail/dovecot/2010-February/047190.html</a> [3] <a href="http://dovecot.org/pipermail/dovecot/2010-February/047058.html">http://dovecot.org/pipermail/dovecot/2010-February/047058.html</a> [4] <a href="http://dovecot.org/releases/1.2/dovecot-1.2.11.tar.gz">http://dovecot.org/releases/1.2/dovecot-1.2.11.tar.gz</a> CVE Request: [5] <a href="http://www.openwall.com/lists/oss-security/2010/03/10/6">http://www.openwall.com/lists/oss-security/2010/03/10/6</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Dovecot | >=1.2.0<1.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-572268 is categorized as a denial of service issue impacting Dovecot.
To fix REDHAT-BUG-572268, upgrade Dovecot to version 1.2.11 or later.
Dovecot versions from 1.2.0 to 1.2.10 are affected by REDHAT-BUG-572268.
The main issue addressed in REDHAT-BUG-572268 is a denial of service vulnerability.
Yes, the release note for REDHAT-BUG-572268 can be found in the upstream announcement by Dovecot.