v2.3.5.2 released
18 Apr
2019
18 Apr
'19
12:05 p.m.
https://dovecot.org/releases/2.3/dovecot-2.3.5.2.tar.gz https://dovecot.org/releases/2.3/dovecot-2.3.5.2.tar.gz.sig Binary packages in https://repo.dovecot.org/
- CVE-2019-7524: Missing input buffer size validation leads into arbitrary buffer overflow when reading fts or pop3 uidl header from Dovecot index. Exploiting this requires direct write access to the index files.
Aki Tuomi Open-Xchange oy
2047
Age (days ago)
2047
Last active (days ago)
0 comments
1 participants
participants (1)
-
Aki Tuomi