Bug 1696152 (CVE-2019-7524)
Summary: | CVE-2019-7524 dovecot: Buffer overflow in indexer-worker process results in privilege escalation | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Dhananjay Arunesh <darunesh> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | anon.amish, bennie.joubert, janfrode, mailinglists, mhlavink |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | dovecot 2.3.5.1, dovecot 2.2.36.3 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2020-03-31 22:33:50 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1696156, 1700398 | ||
Bug Blocks: | 1696154 |
Description
Dhananjay Arunesh
2019-04-04 08:55:12 UTC
External References: https://dovecot.org/list/dovecot-news/2019-March/000403.html Created dovecot tracking bugs for this issue: Affects: fedora-all [bug 1696156] Analysis: Dovecot during its normal operation creates index files which makes reading of the email easier. Each inbox has a set of index files which are created from the emails in the inbox. When index files are disabled they are stored in memory. Only local user who owns the inbox for the particular account has access to the index files. In order to trigger the security flaw, the attacker needs to have local access to the dovecot.index.log file and must be able to manipulate it. Later when dovecot indexer-worker tries to parse the file, it could result in a stack-based buffer overflow and a crash. Code execution is quite possible here specially in the older versions where security technology like StackGuard etc are not enabled. This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1062 https://access.redhat.com/errata/RHSA-2020:1062 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-7524 |