Skip to content

dovecot requires update #223

Description

@vtoc

https://www.openwall.com/lists/oss-security/2019/08/28/3

Vulnerable version: All versions prior to 2.3.7.2 and 2.2.36.4

This vulnerability allows for out-of-bounds writes to objects stored on
the heap up to 8096 bytes in pre-login phase, and 65536 bytes post-login
phase, allowing sufficiently skilled attacker to perform complicated
attacks that can lead to leaking private information or remote code
execution. Abuse of this bug is very difficult to observe, as it does
not necessarily cause a crash. Attempts to abuse this bug are not
directly evident from logs.

Activity

  1. self-assigned this
    on Sep 16, 2019
  2. jperkin commented on Sep 16, 2019

    @jperkin
    Collaborator

    Available in trunk since Sept 9 and 2018Q4 since Sept 11.

  3. jperkin commented on Sep 16, 2019

    @jperkin
    Collaborator

    Backported to 2016Q4 too, packages now available (pending mirror catchup).

  4. added a commit that references this issue on Sep 18, 2019
    28bd29a
  5. added a commit that references this issue on Oct 29, 2019
  6. added a commit that references this issue on Jan 3, 2020
  7. added a commit that references this issue on Feb 6, 2020
  8. added a commit that references this issue on Mar 12, 2020
  9. added a commit that references this issue on Mar 26, 2020
    97971c3
  10. added a commit that references this issue on Jun 7, 2020
  11. 92 remaining items

  12. added a commit that references this issue on Jun 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions