SB2011052502 - Multiple vulnerabilities in Dovecot



SB2011052502 - Multiple vulnerabilities in Dovecot

Published: May 25, 2011 Updated: August 11, 2020

Security Bulletin ID SB2011052502
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2011-1929)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.


2) Configuration (CVE-ID: CVE-2011-2166)

The vulnerability allows a remote #AU# to read and manipulate data.

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.


3) Path traversal (CVE-ID: CVE-2011-2167)

The vulnerability allows a remote #AU# to read and manipulate data.

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.


Remediation

Install update from vendor's website.