SB2019032834 - Stack-based buffer overflow in dovecot (Alpine package)
Published: March 28, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2019-7524)
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when reading FTS or POP3-UIDL header from dovecot index. A local user can modify Dovecot index, trigger stack-based buffer overflow and execute arbitrary code on the target system with privileges of the Dovecot process.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=330109cbd42739e383036be3ebef566fe4bded3f
- https://git.alpinelinux.org/aports/commit/?id=601d2a466efe1b4da01cec77024c25c07206b47e
- https://git.alpinelinux.org/aports/commit/?id=31b384b0fc060368553c2b5da5980ff5625997b5
- https://git.alpinelinux.org/aports/commit/?id=471cf80f4f70e2cd9766b70608e0894e1336c52f
- https://git.alpinelinux.org/aports/commit/?id=b37a739e81ca9a8962a75c6a3675c5a20b86ae11