CVE-2019-7524

Related Vulnerabilities: CVE-2019-7524  

Impact: Moderate Public Date: 2019-03-28 CWE: CWE-120->CWE-284 Bugzilla: 1696152: CVE-2019-7524 dovecot: buffer overflow in indexer-worker process results in privilege escalation In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.

The MITRE CVE dictionary describes this issue as:

In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.

Find out more about CVE-2019-7524 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.8
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 7 dovecot Under investigation
Red Hat Enterprise Linux 6 dovecot Under investigation
Red Hat Enterprise Linux 5 dovecot Under investigation

External References