Stack-based buffer overflow in Dovecot - CVE-2019-7524

 

Stack-based buffer overflow in Dovecot - CVE-2019-7524

Published: March 28, 2019


Vulnerability identifier: #VU18089
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2019-7524
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when reading FTS or POP3-UIDL header from dovecot index. A local user can modify Dovecot index, trigger stack-based buffer overflow and execute arbitrary code on the target system with privileges of the Dovecot process.


Affected software

Dovecot
Gentoo Linux
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Opensuse
Fedora
dovecot (Alpine package)
dovecot (Debian package)
dovecot (Ubuntu package)
dovecot (Red Hat package)
dovecot

How to mitigate CVE-2019-7524

Install updates from vendor's website.

Dovecot - addressed in versions 2.2.36.3, 2.3.5.1
dovecot (Alpine package) - update to 2.2.36.3-r0
dovecot (Debian package) - update to 1:2.2.27-3+deb9u4
dovecot (Ubuntu package) - addressed in versions 1:2.2.9-1ubuntu2.6, 1:2.2.22-1ubuntu2.10, 1:2.2.33.2-1ubuntu4.3, 1:2.3.2.1-1ubuntu3.2
dovecot (Red Hat package) - update to 2.2.36-6.el7
dovecot - addressed in versions 2.3.6-3.fc29, 2.3.6-3.fc30

External References

Related Security Bulletins