Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Ubuntu 18.04 LTS USN-3928-1 Moderate: Dovecot Privilege Escalation

Ubuntu Large Esm H500
Dovecot could be made to crash or run programs as an administrator if it opened a specially crafted file.
=========================================================================Ubuntu Security Notice USN-3928-1
April 01, 2019

dovecot vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.10
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Dovecot could be made to crash or run programs as an administrator
if it opened a specially crafted file.

Software Description:
- dovecot: IMAP and POP3 email server

Details:

It was discovered that Dovecot incorrectly handled reading certain headers
from the index. A local attacker could possibly use this issue to escalate
privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
  dovecot-core                    1:2.3.2.1-1ubuntu3.2

Ubuntu 18.04 LTS:
  dovecot-core                    1:2.2.33.2-1ubuntu4.3

Ubuntu 16.04 LTS:
  dovecot-core                    1:2.2.22-1ubuntu2.10

Ubuntu 14.04 LTS:
  dovecot-core                    1:2.2.9-1ubuntu2.6

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3928-1
  CVE-2019-7524

Package Information:
  https://launchpad.net/ubuntu/+source/dovecot/1:2.3.2.1-1ubuntu3.2
  https://launchpad.net/ubuntu/+source/dovecot/1:2.2.33.2-1ubuntu4.3
  https://launchpad.net/ubuntu/+source/dovecot/1:2.2.22-1ubuntu2.10
  https://launchpad.net/ubuntu/+source/dovecot/1:2.2.9-1ubuntu2.6

Ubuntu 18.04 LTS USN-3928-1 Moderate: Dovecot Privilege Escalation

ubuntu
Calendar Grey April 1, 2019
Dist Ubuntu Esm H88
Dovecot flaw in Ubuntu might permit adversaries to disrupt the service or execute commands with higher privileges.
Dovecot could be made to crash or run programs as an administrator if it opened a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10: dovecot-core 1:2.3.2.1-1ubuntu3.2 Ubuntu 18.04 LTS: dovecot-core 1:2.2.33.2-1ubuntu4.3 Ubuntu 16.04 LTS: dovecot-core 1:2.2.22-1ubuntu2.10 Ubuntu 14.04 LTS: dovecot-core 1:2.2.9-1ubuntu2.6 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3928-1

CVE-2019-7524

Severity
important
Lowest
Low
Medium
High
Critical

April 01, 2019

Package Information

https://launchpad.net/ubuntu/+source/dovecot/1:2.3.2.1-1ubuntu3.2 https://launchpad.net/ubuntu/+source/dovecot/1:2.2.33.2-1ubuntu4.3 https://launchpad.net/ubuntu/+source/dovecot/1:2.2.22-1ubuntu2.10 https://launchpad.net/ubuntu/+source/dovecot/1:2.2.9-1ubuntu2.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here