Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 172795 - net-mail/dovecot 1.0_rc29 has a security flaw in its zlib plugin
Summary: net-mail/dovecot 1.0_rc29 has a security flaw in its zlib plugin
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://www.dovecot.org/list/dovecot-n...
Whiteboard: C4? [noglsa] jaervosz
Keywords:
: 186225 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-03-30 15:20 UTC by Roy Marples (RETIRED)
Modified: 2011-10-30 22:39 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Roy Marples (RETIRED) gentoo-dev 2007-03-30 15:20:11 UTC
FTA
zlib plugin allows opening gzipped mboxes as read-only mailboxes.
However when using it, the mailbox name checks are bypassed so it's
possible to open for example "../otheruser/somefile.gz". Only valid
gzipped mbox files can be opened, and only if their name ends with
".gz".

You can fix this by upgrading to v1.0.rc29 (available soon) or with this
patch: http://dovecot.org/list/dovecot-cvs/2007-March/008488.html

I don't think this matters much though. zlib plugin is rarely used, and
those who do use it are probably using Dovecot with systems users
(per-user UIDs), so the imap process wouldn't have access to other
users' mbox files anyway.

I found this problem when I was cleaning up the code in CVS HEAD.

--------------------------------------------------------------------------

I've added dovecot-1.0_rc29 to portage.
This should not affect us by default as 1, we don't use any plugins by default and 2, we use maildir as default.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-03-30 15:32:05 UTC
Thx Roy.

Arches please test and mark stable. Target keywords are:

dovecot-1.0_rc28.ebuild:KEYWORDS="alpha amd64 ppc sparc x86 ~x86-fbsd"
Comment 2 Andrej Kacian (RETIRED) gentoo-dev 2007-03-30 20:37:28 UTC
(In reply to comment #1)
> Thx Roy.
> 
> Arches please test and mark stable. Target keywords are:
> 
> dovecot-1.0_rc28.ebuild:KEYWORDS="alpha amd64 ppc sparc x86 ~x86-fbsd"
> 

Um, _rc29 is the one with the security fix.

x86 stable
Comment 3 Tobias Scherbaum (RETIRED) gentoo-dev 2007-04-02 18:36:51 UTC
ppc stable
Comment 4 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2007-04-02 20:13:12 UTC
alpha stable
Comment 5 Gustavo Zacarias (RETIRED) gentoo-dev 2007-04-03 18:05:32 UTC
sparc stable.
Comment 6 Peter Weller (RETIRED) gentoo-dev 2007-04-07 06:20:42 UTC
Stable on amd64
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-04-11 10:30:50 UTC
This one is ready for GLSA decision. I vote NO.
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-05-03 18:42:08 UTC
voting NO too.
Comment 9 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-03 18:52:32 UTC
Closing. Feel free to reopen if you disagree.
Comment 10 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-03 15:06:54 UTC
*** Bug 186225 has been marked as a duplicate of this bug. ***