Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 445844 - <net-mail/dovecot-2.1.12-r1: version bump
Summary: <net-mail/dovecot-2.1.12-r1: version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Eray Aslan
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-12-03 19:42 UTC by Agostino Sarubbo
Modified: 2012-12-16 15:19 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-12-03 19:42:13 UTC
From $URL :

Dovecot 2.1.11 was released and includes a fix for a crash condition
when the IMAP server was issued a SEARCH command with multiple KEYWORD
parameters.  An authenticated remote user could use this flaw to crash
Dovecot.

The upstream fix was to remove the keyword merging code.  This code
does not exist in Dovecot 1.x, but it does affect 2.x versions, at least
as far back as 2.0.9 (earliest version I checked).

References:

http://www.dovecot.org/list/dovecot-news/2012-November/000235.html
http://secunia.com/advisories/51455
http://hg.dovecot.org/dovecot-2.1/rev/0306792cc843
https://bugzilla.redhat.com/show_bug.cgi?id=883060
Comment 1 Eray Aslan gentoo-dev 2012-12-04 11:17:49 UTC
@security: dovecot-2.1.11 is not a good release.  There are reports of having problems building sieve plugin.  Please consider stabilizing =net-mail/dovecot-2.1.12-r1. Thank you.
Comment 2 Agostino Sarubbo gentoo-dev 2012-12-04 11:24:31 UTC
Arches, please test and mark stable:
=net-mail/dovecot-2.1.12-r1
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"
Comment 3 Agostino Sarubbo gentoo-dev 2012-12-04 13:28:14 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2012-12-04 13:29:08 UTC
x86 stable
Comment 5 Agostino Sarubbo gentoo-dev 2012-12-04 13:30:06 UTC
ppc stable
Comment 6 Agostino Sarubbo gentoo-dev 2012-12-04 13:30:59 UTC
ppc64 stable
Comment 7 Eray Aslan gentoo-dev 2012-12-04 21:21:49 UTC
(In reply to comment #0)
> An authenticated remote user could use this flaw to crash
> Dovecot.

"A user can crash his/her own IMAP session" says upstream - not the whole IMAP server.

http://www.dovecot.org/list/dovecot/2012-December/069793.html

FYI
Comment 8 Jeroen Roovers (RETIRED) gentoo-dev 2012-12-04 23:16:26 UTC
Stable for HPPA.
Comment 9 Anthony Basile gentoo-dev 2012-12-05 02:23:13 UTC
stable arm
Comment 10 Raúl Porcel (RETIRED) gentoo-dev 2012-12-15 17:51:19 UTC
alpha/ia64/s390/sh/sparc stable
Comment 11 Sean Amoss (RETIRED) gentoo-dev Security 2012-12-16 15:19:43 UTC
Thanks, everyone.

(In reply to comment #7)
> (In reply to comment #0)
> > An authenticated remote user could use this flaw to crash
> > Dovecot.
> 
> "A user can crash his/her own IMAP session" says upstream - not the whole
> IMAP server.
> 
> http://www.dovecot.org/list/dovecot/2012-December/069793.html
> 
> FYI

Thanks, Eras. CVE-2012-5620 has been rejected [1] as this is not a vulnerability. 

Removing from security and closing since arches are finished. 

[1] http://www.openwall.com/lists/oss-security/2012/12/05/1