REDHAT-BUG-706286: Medium severity dovecot vulnerability
Dovecot has released version 1.2.17 [1] and 2.0.13 [2] to address a potential crash, and possibly mailbox corruption, when dovecot parsed header names that contained NUL characters. This was due to a pointer possibly pointing past allocated memory. An upstream patch [3] is available.
[1] http://dovecot.org/pipermail/dovecot/2011-May/059086.html [2] http://dovecot.org/pipermail/dovecot/2011-May/059085.html [3] http://hg.dovecot.org/dovecot-1.1/rev/3698dfe0f21c
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-706286?
REDHAT-BUG-706286 is considered a critical vulnerability due to its potential to cause crashes and mailbox corruption.
How do I fix REDHAT-BUG-706286?
To fix REDHAT-BUG-706286, update Dovecot to version 1.2.17 or 2.0.13 or later.
What products are affected by REDHAT-BUG-706286?
The affected products of REDHAT-BUG-706286 include Dovecot versions from 1.2.17 to 2.0.13.
What is the cause of REDHAT-BUG-706286?
REDHAT-BUG-706286 is caused by a pointer potentially pointing past allocated memory when Dovecot parses header names with NUL characters.
Is there an upstream patch available for REDHAT-BUG-706286?
Yes, an upstream patch is available to address the vulnerability described in REDHAT-BUG-706286.