[Dovecot] Possible CPU Denial-Of-Service attack to dovecot IMAP.

Timo Sirainen tss at iki.fi
Sun Feb 28 16:21:58 EET 2010


On Sun, 2010-02-28 at 15:43 +0200, Timo Sirainen wrote:
> Interestingly enough, that's the same bug I just fixed today (after
> spending several days trying to figure it out):
> http://hg.dovecot.org/dovecot-2.0/rev/de2798fbbae6
> 
> Hmm. Since it's causing also real problems, I suppose I should fix it
> for v1.2 too.. The problem anyway is only with v1.2 + mbox combination,
> nothing else.

Here's a workaround for v1.2:
http://hg.dovecot.org/dovecot-1.2/rev/6c9f2ed821df

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: This is a digitally signed message part
Url : http://dovecot.org/pipermail/dovecot/attachments/20100228/8958880d/attachment.bin 


More information about the dovecot mailing list