CVE-2019-11500

Bug #1842007 reported by Bryce Harrington
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
dovecot (Ubuntu)
Fix Released
High
Unassigned

Bug Description

  * SECURITY UPDATE: IMAP do not properly handled NULL byte - bounds
    heap memory writes
    - debian/patches/CVE-2019-11500-*.patch: doesn't accept strings with
      NULs in src/lib-imap/imap-parser.c and
      pigeonhole/src/lib-managesieve/managesieve-parser.c,
      make sure str_unescape won't be writing past allocated memory
      in src/lib-imap/imap-parser.c and
      pieonhole/src/lig-managesieve/managesieve-parser.c.
    - CVE-2019-11500

Tags: patch
Revision history for this message
Bryce Harrington (bryce) wrote :
Changed in dovecot (Ubuntu):
importance: Undecided → High
status: New → Triaged
Revision history for this message
Bryce Harrington (bryce) wrote :

Changes LGTM, thanks for identifying them. Upload tag pushed, and package uploaded:

$ git push -f pkg upload/1%2.3.4.1-5ubuntu3
Counting objects: 5, done.
Delta compression using up to 6 threads.
Compressing objects: 100% (5/5), done.
Writing objects: 100% (5/5), 871 bytes | 217.00 KiB/s, done.
Total 5 (delta 3), reused 0 (delta 0)
To ssh://git.launchpad.net/~usd-import-team/ubuntu/+source/dovecot
 + 0cb9544bd...dd6d659a5 upload/1%2.3.4.1-5ubuntu3 -> upload/1%2.3.4.1-5ubuntu3 (forced update)

$ dput ubuntu dovecot_2.3.4.1-5ubuntu3_source.changes
Checking signature on .changes
gpg: /home/bryce/ubuntu/Dovecot/sponsor.lp1842007/dovecot_2.3.4.1-5ubuntu3_source.changes: Valid signature from E603B2578FB8F0FB
Checking signature on .dsc
gpg: /home/bryce/ubuntu/Dovecot/sponsor.lp1842007/dovecot_2.3.4.1-5ubuntu3.dsc: Valid signature from E603B2578FB8F0FB
Uploading to ubuntu (via ftp to upload.ubuntu.com):
  Uploading dovecot_2.3.4.1-5ubuntu3.dsc: done.
  Uploading dovecot_2.3.4.1-5ubuntu3.debian.tar.xz: done.
  Uploading dovecot_2.3.4.1-5ubuntu3_source.buildinfo: done.
  Uploading dovecot_2.3.4.1-5ubuntu3_source.changes: done.
Successfully uploaded packages.

Changed in dovecot (Ubuntu):
status: Triaged → Fix Committed
Alex Murray (alexmurray)
information type: Private Security → Public Security
tags: added: patch
Bryce Harrington (bryce)
Changed in dovecot (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.