Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Fedora 23: Dovecot Security Advisory 2015-46afff8d90 Buffer Overflow

fedora
Calendar Grey November 15, 2015
Scroller Fedora
Dovecot's latest security patch addresses critical buffer overflow vulnerabilities and improves message processing issues within Fedora systems. Learn additional details about the upgrades.
* dovecot updated to 2.2.19 * mdbox: Rebuilding could have caused message's reference count to overflow the 16bit number in some situations, causing problems when trying to expun...

Summary

Dovecot is an IMAP server for Linux/UNIX-like systems, written with security

primarily in mind. It also contains a small POP3 server. It supports mail

in either of maildir or mbox formats.

The SQL drivers and authentication plug-ins are in their subpackages.

Update Information:

* dovecot updated to 2.2.19 * mdbox: Rebuilding could have caused message's reference count to overflow the 16bit number in some situations, causing problems when trying to expunge the duplicates. * Various search fixes (fts, solr, tika, lib-charset, indexer) * Various virtual plugin fixes * Various fixes and optimizations to dsync, imapc and pop3-migration * imap: Various RFC compliancy and crash fixes to NOTIFY * pigeonhole updated to 0.4.9 * ManageSieve: Fixed an assert failure occurring when a client disconnects during the GETSCRIPT command. - doveadm sieve plugin: Fixed incorrect initialization (mem leaks) of mail user. - sieve-filter command line tool: Fixed handling of failure-related implicit keep when there is an explicit default destination folder. - lib-sieve: Fixed bug in RFC5322 header folding.

Change Log

References


[ 1 ] Bug #1276607 - dovecot: Buffer overflow when handling pop3_deleted_flag setting https://bugzilla.redhat.com/show_bug.cgi?id=1276607

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update dovecot' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: dovecot
Product: Fedora 23
Version: 2.2.19
Release: 1.fc23
URL: Summary : Secure imap and pop3 server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.