ports/128698: [vuxml] new entry for Dovecot 1.1.4-1.1.5

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <FreeBSD-gnats-submit@...>
Date: Saturday, November 8, 2008 - 10:03 am

>Number: 128698

Code Labs

Not applicable.

>Description:

Citing from http://www.dovecot.org/list/dovecot-news/2008-October/000089.html
-----
The invalid message address parsing bug is pretty important since it
allows a remote user to send broken mail headers and prevent the
recipient from accessing the mailbox afterwards, because the process
will always just crash trying to parse the header. This is assuming that
the IMAP client uses FETCH ENVELOPE command, not all do. Note that it
doesn't affect versions older than v1.1.4.
-----

Currently, FreeBSD's Dovecot from ports is build from the 1.1.3 release
and I doubt that it will be upgraded to something <= 1.1.6, since 1.1.6
is out. But who knows.

>How-To-Repeat:

Look at
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4907
and references therein.

>Fix:

Possibly, the new VuXML entry can be added:
--- dovecot-08.11.2008.xml begins here ---

dovecot -- invalid message address parsing bug

dovecot
dovecot-devel
1.1.41.1.6

Dovecot reports:

The invalid message address parsing bug is pretty
important since it allows a remote user to send broken
mail headers and prevent the recipient from accessing
the mailbox afterwards, because the process will always
just crash trying to parse the header. This is assuming
that the IMAP client uses FETCH ENVELOPE command, not
all do. Note that it doesn't affect versions older than
v1.1.4.

CVE-2008-4907
http://www.dovecot.org/list/dovecot-news/2008-October/000089.html
http://secunia.com/advisories/32479/
http://xforce.iss.net/xforce/xfdb/46227/
http://www.securityfocus.com/bid/31997/

2008-10-30
2008-11-08

--- dovecot-08.11.2008.xml ends here ---

As I said, I greatly doubt that official FreeBSD ports will ever have
these versions of Dovecot, but people can update their ports to receive
the new Dovecot versions, so there can be some reasons to add it.

The only PR that contains Dovecot is ports/128469 and it upgrades the
port to the "safe" version 1.1.6.

_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
ports/128698: [vuxml] new entry for Dovecot 1.1.4-1.1.5, Eygene Ryabinkin, (Sat Nov 8, 10:03 am)
RE: CVE-2008-4609, olli hauer, (Tue Sep 8, 4:58 pm)
OCF, Raja FreeBSD, (Thu Sep 20, 5:49 am)
Re: OPIE Challenge sequence, Ivan Grover, (Tue Jul 8, 9:41 am)
Re: IPSEC help, john decot, (Sat Nov 17, 5:06 am)
Re: OPIE Challenge sequence, Dag-Erling Smørgrav, (Tue Jul 8, 11:37 am)
Re: OPIE Challenge sequence, Ivan Grover, (Wed Jul 9, 2:55 am)
Re: OPIE Challenge sequence, Dag-Erling Smørgrav, (Wed Jul 9, 4:29 am)
Re: OPIE Challenge sequence, Jason Stone, (Tue Jul 8, 3:27 pm)
Re: OPIE Challenge sequence, Ivan Grover, (Wed Jul 9, 4:18 am)
Re: IPSEC help, Shoichi Sakane, (Thu Nov 29, 9:56 pm)
Re: IPSEC help, VANHULLEBUS Yvan, (Mon Nov 19, 5:38 am)
Re: IPSEC help, john decot, (Tue Nov 20, 6:57 am)
Re: IPSEC help, VANHULLEBUS Yvan, (Tue Nov 20, 8:34 am)
Re: IPSEC help, john decot, (Tue Nov 20, 12:46 pm)
Re: IPSEC help, VANHULLEBUS Yvan, (Tue Nov 20, 12:56 pm)
Re: IPSEC help, john decot, (Thu Nov 22, 11:08 am)
Re: IPSEC help, Bjoern Engels, (Tue Nov 20, 7:08 am)
Re: OCF, Mohacsi Janos, (Fri Sep 21, 5:30 am)
Re: OCF, Eygene Ryabinkin, (Fri Sep 21, 11:58 am)