Stack-based buffer overflow in Dovecot - CVE-2019-7524
Published: March 28, 2019
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when reading FTS or POP3-UIDL header from dovecot index. A local user can modify Dovecot index, trigger stack-based buffer overflow and execute arbitrary code on the target system with privileges of the Dovecot process.
Affected software
Gentoo Linux
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Opensuse
Fedora
dovecot (Alpine package)
dovecot (Debian package)
dovecot (Ubuntu package)
dovecot (Red Hat package)
dovecot
How to mitigate CVE-2019-7524
dovecot (Alpine package) - update to 2.2.36.3-r0
dovecot (Debian package) - update to 1:2.2.27-3+deb9u4
dovecot (Ubuntu package) - addressed in versions 1:2.2.9-1ubuntu2.6, 1:2.2.22-1ubuntu2.10, 1:2.2.33.2-1ubuntu4.3, 1:2.3.2.1-1ubuntu3.2
dovecot (Red Hat package) - update to 2.2.36-6.el7
dovecot - addressed in versions 2.3.6-3.fc29, 2.3.6-3.fc30
External References
Related Security Bulletins
- Privilege escalation in Dovecot
- Debian update for dovecot
- Ubuntu update for Dovecot
- Gentoo update for Dovecot
- OpenSUSE Linux update for dovecot22
- OpenSUSE Linux update for dovecot23
- Arch Linux update for dovecot
- Arch Linux update for dovecot
- Red Hat Enterprise Linux 7 update for dovecot
- Amazon Linux AMI update for dovecot
- Stack-based buffer overflow in dovecot (Alpine package)
- Fedora 30 update for dovecot
- Fedora 29 update for dovecot