v2.3.5.2 released
18 Apr
2019
18 Apr
'19
12:05 p.m.
https://dovecot.org/releases/2.3/dovecot-2.3.5.2.tar.gz https://dovecot.org/releases/2.3/dovecot-2.3.5.2.tar.gz.sig Binary packages in https://repo.dovecot.org/
- CVE-2019-7524: Missing input buffer size validation leads into arbitrary buffer overflow when reading fts or pop3 uidl header from Dovecot index. Exploiting this requires direct write access to the index files.
Aki Tuomi Open-Xchange oy
2081
Age (days ago)
2081
Last active (days ago)
0 comments
1 participants
participants (1)
-
Aki Tuomi