Debian Security Update DSA-4510 dovecot - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,844
Reaction score
74
Credits
-1,257
Nick Roessler and Rafi Rubin discovered that the IMAP and ManageSieve protocol parsers in the Dovecot email server do not properly validate input (both pre- and post-login). A remote attacker can take advantage of this flaw to trigger out of bounds heap memory writes, leading to information leaks or potentially the execution of arbitrary code.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top