Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
BID:21183
CVE-2006-5973 |Info
Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
| Bugtraq ID: | 21183 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5973 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2006 12:00AM |
| Updated: | Jan 25 2007 04:29PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 rPath rPath Linux 1 Redhat Fedora Core5 Dovecot Dovecot 1.0.RC9 Dovecot Dovecot 1.0.RC8 Dovecot Dovecot 1.0.RC7 Dovecot Dovecot 1.0.RC6 Dovecot Dovecot 1.0.RC5 Dovecot Dovecot 1.0.RC4 Dovecot Dovecot 1.0.RC3 Dovecot Dovecot 1.0.RC2 Dovecot Dovecot 1.0.RC14 Dovecot Dovecot 1.0.RC13 Dovecot Dovecot 1.0.RC12 Dovecot Dovecot 1.0.RC11 Dovecot Dovecot 1.0.RC10 Dovecot Dovecot 1.0.Beta3 Dovecot Dovecot 1.0.Beta2 Dovecot Dovecot 1.0 Rc1 Dovecot Dovecot 1.0 Beta8 Dovecot Dovecot 1.0 Beta7 Dovecot Dovecot 1.0 |
| Not Vulnerable: |
Dovecot Dovecot 1.0.RC15 |
Discussion
Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
Dovecot is prone to an off-by-one buffer-overflow condition due to an error that results in insufficient memory allocation.
An attacker may exploit this issue to trigger denial-of-service conditions. Presumably, arbitrary code execution may be possible as well.
Versions 1.0test53 to 1.0.rc14 are vulnerable.
Dovecot is prone to an off-by-one buffer-overflow condition due to an error that results in insufficient memory allocation.
An attacker may exploit this issue to trigger denial-of-service conditions. Presumably, arbitrary code execution may be possible as well.
Versions 1.0test53 to 1.0.rc14 are vulnerable.
Exploit / POC
Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
Solution:
The vendor has released a fix for this issue; please see the references for more information.
Dovecot Dovecot 1.0.RC10
Dovecot Dovecot 1.0 Beta8
Dovecot Dovecot 1.0.RC11
Dovecot Dovecot 1.0.RC4
Dovecot Dovecot 1.0.RC5
Dovecot Dovecot 1.0.RC8
Dovecot Dovecot 1.0.Beta2
Dovecot Dovecot 1.0.RC13
Dovecot Dovecot 1.0
Redhat Fedora Core5
Dovecot Dovecot 1.0.RC14
Dovecot Dovecot 1.0.RC2
Dovecot Dovecot 1.0 Rc1
Dovecot Dovecot 1.0.RC3
Dovecot Dovecot 1.0.RC7
Dovecot Dovecot 1.0.RC6
Dovecot Dovecot 1.0 Beta7
Dovecot Dovecot 1.0.RC9
Dovecot Dovecot 1.0.Beta3
Dovecot Dovecot 1.0.RC12
Solution:
The vendor has released a fix for this issue; please see the references for more information.
Dovecot Dovecot 1.0.RC10
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0 Beta8
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC11
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC4
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC5
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC8
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.Beta2
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC13
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Redhat Fedora Core5
-
RedHat dovecot-1.0-0.beta8.3.fc5.i386.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat dovecot-1.0-0.beta8.3.fc5.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat dovecot-1.0-0.beta8.3.fc5.src.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat dovecot-1.0-0.beta8.3.fc5.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat dovecot-debuginfo-1.0-0.beta8.3.fc5.i386.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat dovecot-debuginfo-1.0-0.beta8.3.fc5.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/ -
RedHat dovecot-debuginfo-1.0-0.beta8.3.fc5.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
Dovecot Dovecot 1.0.RC14
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC2
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz -
Ubuntu dovecot-common_1.0.beta3-3ubuntu5.4_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-common_1 .0.beta3-3ubuntu5.4_amd64.deb -
Ubuntu dovecot-common_1.0.beta3-3ubuntu5.4_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-common_1 .0.beta3-3ubuntu5.4_i386.deb -
Ubuntu dovecot-common_1.0.beta3-3ubuntu5.4_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-common_1 .0.beta3-3ubuntu5.4_powerpc.deb -
Ubuntu dovecot-common_1.0.beta3-3ubuntu5.4_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-common_1 .0.beta3-3ubuntu5.4_sparc.deb -
Ubuntu dovecot-common_1.0.rc2-1ubuntu2.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-common_1 .0.rc2-1ubuntu2.1_amd64.deb -
Ubuntu dovecot-common_1.0.rc2-1ubuntu2.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-common_1 .0.rc2-1ubuntu2.1_i386.deb -
Ubuntu dovecot-common_1.0.rc2-1ubuntu2.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-common_1 .0.rc2-1ubuntu2.1_powerpc.deb -
Ubuntu dovecot-common_1.0.rc2-1ubuntu2.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-common_1 .0.rc2-1ubuntu2.1_sparc.deb -
Ubuntu dovecot-imapd_1.0.beta3-3ubuntu5.4_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-imapd_1. 0.beta3-3ubuntu5.4_amd64.deb -
Ubuntu dovecot-imapd_1.0.beta3-3ubuntu5.4_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-imapd_1. 0.beta3-3ubuntu5.4_i386.deb -
Ubuntu dovecot-imapd_1.0.beta3-3ubuntu5.4_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-imapd_1. 0.beta3-3ubuntu5.4_powerpc.deb -
Ubuntu dovecot-imapd_1.0.beta3-3ubuntu5.4_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-imapd_1. 0.beta3-3ubuntu5.4_sparc.deb -
Ubuntu dovecot-imapd_1.0.rc2-1ubuntu2.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-imapd_1. 0.rc2-1ubuntu2.1_amd64.deb -
Ubuntu dovecot-imapd_1.0.rc2-1ubuntu2.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-imapd_1. 0.rc2-1ubuntu2.1_i386.deb -
Ubuntu dovecot-imapd_1.0.rc2-1ubuntu2.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-imapd_1. 0.rc2-1ubuntu2.1_powerpc.deb -
Ubuntu dovecot-imapd_1.0.rc2-1ubuntu2.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-imapd_1. 0.rc2-1ubuntu2.1_sparc.deb -
Ubuntu dovecot-pop3d_1.0.beta3-3ubuntu5.4_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-pop3d_1. 0.beta3-3ubuntu5.4_amd64.deb -
Ubuntu dovecot-pop3d_1.0.beta3-3ubuntu5.4_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-pop3d_1. 0.beta3-3ubuntu5.4_i386.deb -
Ubuntu dovecot-pop3d_1.0.beta3-3ubuntu5.4_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-pop3d_1. 0.beta3-3ubuntu5.4_powerpc.deb -
Ubuntu dovecot-pop3d_1.0.beta3-3ubuntu5.4_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-pop3d_1. 0.beta3-3ubuntu5.4_sparc.deb -
Ubuntu dovecot-pop3d_1.0.rc2-1ubuntu2.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-pop3d_1. 0.rc2-1ubuntu2.1_amd64.deb -
Ubuntu dovecot-pop3d_1.0.rc2-1ubuntu2.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-pop3d_1. 0.rc2-1ubuntu2.1_i386.deb -
Ubuntu dovecot-pop3d_1.0.rc2-1ubuntu2.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-pop3d_1. 0.rc2-1ubuntu2.1_powerpc.deb -
Ubuntu dovecot-pop3d_1.0.rc2-1ubuntu2.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot-pop3d_1. 0.rc2-1ubuntu2.1_sparc.deb
Dovecot Dovecot 1.0 Rc1
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC3
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC7
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC6
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0 Beta7
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC9
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.Beta3
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
Dovecot Dovecot 1.0.RC12
-
Dovecot file-cache-buffer-overflow-fix.diff
http://dovecot.org/patches/1.0/file-cache-buffer-overflow-fix.diff -
Dovecot dovecot-1.0.rc15.tar.gz
http://www.dovecot.org/releases/dovecot-1.0.rc15.tar.gz
References
Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
References:
References:
- Vendor Homepage (Dovecot)
- Dovecot IMAP/POP3 server: Off-by-one buffer overflow (Timo Sirainen)