Subject: | |
From: | |
Reply To: | |
Date: | Wed, 21 May 2008 13:13:58 -0500 |
Content-Type: | text/plain |
Parts/Attachments: |
|
|
Synopsis: Low: dovecot security and bug fix update
Issue date: 2008-05-21
CVE Names: CVE-2007-2231 CVE-2007-4211 CVE-2007-6598
CVE-2008-1199
A flaw was discovered in the way Dovecot handled the "mail_extra_groups"
option. An authenticated attacker with local shell access could leverage
this flaw to read, modify, or delete other users mail that is stored on
the mail server. (CVE-2008-1199)
This issue did not affect the default Red Hat Enterprise Linux 5 Dovecot
configuration. This update adds two new configuration options --
"mail_privileged_group" and "mail_access_groups" -- to minimize the usage
of additional privileges.
A directory traversal flaw was discovered in Dovecot's zlib plug-in. An
authenticated user could use this flaw to view other compressed mailboxes
with the permissions of the Dovecot process. (CVE-2007-2231)
A flaw was found in the Dovecot ACL plug-in. User with only insert
permissions for a mailbox could use the "COPY" and "APPEND" commands to set
additional message flags. (CVE-2007-4211)
A flaw was found in a way Dovecot cached LDAP query results in certain
configurations. This could possibly allow authenticated users to log in as
a different user who has the same password. (CVE-2007-6598)
As well, this updated package fixes the following bugs:
* configuring "userdb" and "passdb" to use LDAP caused Dovecot to hang. A
segmentation fault may have occurred. In this updated package, using an
LDAP backend for "userdb" and "passdb" no longer causes Dovecot to hang.
* the Dovecot "login_process_size" limit was configured for 32-bit systems.
On 64-bit systems, when Dovecot was configured to use either IMAP or POP3,
the log in processes crashed with out-of-memory errors. Errors such as the
following were logged:
pop3-login: pop3-login: error while loading shared libraries:
libsepol.so.1: failed to map segment from shared object: Cannot allocate
memory
In this updated package, the "login_process_size" limit is correctly
configured on 64-bit systems, which resolves this issue.
Note: this updated package upgrades dovecot to version 1.0.7. For
further details, refer to the Dovecot changelog:
http://koji.fedoraproject.org/koji/buildinfo?buildID=23397
SL 5.x
SRPMS:
dovecot-1.0.7-2.el5.src.rpm
i386:
dovecot-1.0.7-2.el5.i386.rpm
x86_64:
dovecot-1.0.7-2.el5.x86_64.rpm
-Connie Sieh
-Troy Dawson
|
|
|