|
|
Log in / Subscribe / Register

Debian alert DLA-1901-1 (dovecot)

From:  Roberto C. Sánchez <roberto@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 1901-1] dovecot security update
Date:  Thu, 29 Aug 2019 15:02:49 -0400
Message-ID:  <20190829190249.xdvamgxdziphva5n@connexer.com>

Package : dovecot Version : 1:2.2.13-12~deb8u7 CVE ID : CVE-2019-11500 Nick Roessler and Rafi Rubin discovered that the IMAP and ManageSieve protocol parsers in the Dovecot email server do not properly validate input (both pre- and post-login). A remote attacker can take advantage of this flaw to trigger out of bounds heap memory writes, leading to information leaks or potentially the execution of arbitrary code. For Debian 8 "Jessie", this problem has been fixed in version 1:2.2.13-12~deb8u7. We recommend that you upgrade your dovecot packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds