Bug 216508 (CVE-2006-5973)

Summary: CVE-2006-5973 dovecot off by one DoS
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: dovecotAssignee: Tomas Janousek <tjanouse>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 6CC: tss, wtogami
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,source=gentoo,reported=20061120,public=20061119
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-12-21 14:28:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2006-11-20 21:23:01 UTC
Dovecot upstream has found and fixed an off by one flaw in the dovecot server
when the mmap_disable=yes setting is used in the dovecot configuration file.

More information can be found in the upstream announcement:
http://www.dovecot.org/list/dovecot-news/2006-November/000023.html

This flaw also affects FC5

Comment 1 Fedora Update System 2006-12-05 21:59:35 UTC
dovecot-1.0-1.rc15.fc6 has been pushed for fc6, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.

Comment 2 Fedora Update System 2006-12-18 18:57:18 UTC
dovecot-1.0-1.rc15.fc6 has been pushed for fc6, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.

Comment 3 Fedora Update System 2006-12-23 19:13:33 UTC
dovecot-1.0-0.beta8.3.fc5 has been pushed for fc5, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.

Comment 4 Fedora Update System 2006-12-27 06:02:18 UTC
dovecot-1.0-0.beta8.3.fc5 has been pushed for fc5, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.