Description: A vulnerability has been reported in Dovecot, which can be exploited by malicious users to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
The vulnerability is caused due to an off-by-one error when the dovecot.index.cache file is read into memory. If the "mmap_disable" option is set to "yes", this can be exploited to cause a one-byte buffer overflow.
The vulnerability is reported in version 1.0test53 through 1.0.rc14.
Solution: Update to version 1.0rc15.
Provided and/or discovered by: Reported by the vendor.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.