Bug 216508 (CVE-2006-5973) - CVE-2006-5973 dovecot off by one DoS
Summary: CVE-2006-5973 dovecot off by one DoS
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2006-5973
Product: Fedora
Classification: Fedora
Component: dovecot
Version: 6
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Tomas Janousek
QA Contact:
URL:
Whiteboard: impact=moderate,source=gentoo,reporte...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-11-20 21:23 UTC by Josh Bressers
Modified: 2014-01-21 22:55 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2006-12-21 14:28:29 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2006-11-20 21:23:01 UTC
Dovecot upstream has found and fixed an off by one flaw in the dovecot server
when the mmap_disable=yes setting is used in the dovecot configuration file.

More information can be found in the upstream announcement:
http://www.dovecot.org/list/dovecot-news/2006-November/000023.html

This flaw also affects FC5

Comment 1 Fedora Update System 2006-12-05 21:59:35 UTC
dovecot-1.0-1.rc15.fc6 has been pushed for fc6, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.

Comment 2 Fedora Update System 2006-12-18 18:57:18 UTC
dovecot-1.0-1.rc15.fc6 has been pushed for fc6, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.

Comment 3 Fedora Update System 2006-12-23 19:13:33 UTC
dovecot-1.0-0.beta8.3.fc5 has been pushed for fc5, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.

Comment 4 Fedora Update System 2006-12-27 06:02:18 UTC
dovecot-1.0-0.beta8.3.fc5 has been pushed for fc5, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.