FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-1929

This CVE name corresponds to:

Entered Topic
2011-08-19 dovecot -- denial of service vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-1929
Phase Assigned(20110509)

Description

lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.

References

Source Reference
MLIST [dovecot] 20110511 v1.2.17 released
MLIST [dovecot] 20110511 v2.0.13 released
MLIST [oss-security] 20110518 Dovecot releases
MLIST [oss-security] 20110519 Re: Dovecot releases
MLIST [oss-security] 20110519 Re: Dovecot releases
CONFIRM http://hg.dovecot.org/dovecot-1.1/rev/3698dfe0f21c
CONFIRM http://www.dovecot.org/doc/NEWS-1.2
CONFIRM http://www.dovecot.org/doc/NEWS-2.0
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=706286
DEBIAN DSA-2252
FEDORA FEDORA-2011-7258
FEDORA FEDORA-2011-7268
FEDORA FEDORA-2011-7612
MANDRIVA MDVSA-2011:101
REDHAT RHSA-2011:1187
SUSE openSUSE-SU-2011:0540
UBUNTU USN-1143-1
BID 47930
OSVDB 72495
SECUNIA 44712
SECUNIA 44756
SECUNIA 44771
SECUNIA 44827
SECUNIA 44683
XF dovecot-header-name-dos(67589)