Dovecot: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201110-04 / Dovecot |
| Release Date |
October 10, 2011 |
| Latest Revision |
October 10, 2011: 2 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-mail/dovecot |
<
2.0.13 |
revision >=
1.2.17,
>=
2.0.13 |
All supported architectures
|
Related bugreports:
#286844, #293954, #314533, #368653
Synopsis
Multiple vulnerabilities were found in Dovecot, the worst of which
allowing for remote execution of arbitrary code.
2.
Impact Information
Background
Dovecot is an IMAP and POP3 server written with security primarily in
mind.
Description
Multiple vulnerabilities have been discovered in Dovecot. Please review
the CVE identifiers referenced below for details.
Impact
A remote attacker could exploit these vulnerabilities to cause the
remote execution of arbitrary code, or a Denial of Service condition, to
conduct directory traversal attacks, corrupt data, or disclose
information.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Dovecot 1 users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-mail/dovecot-1.2.17"
|
All Dovecot 2 users should upgrade to the latest version:
Code Listing 3.2: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-mail/dovecot-2.0.13"
|
NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since May 28, 2011. It is likely that your system is already no
longer affected by this issue.
4.
References
|