DSA-2252-1 dovecot -- programming error

Related Vulnerabilities: CVE-2011-1929  

It was discovered that the message header parser in the Dovecot mail server parsed NUL characters incorrectly, which could lead to denial of service through malformed mail headers. The oldstable distribution (lenny) is not affected. For the stable distribution (squeeze), this problem has been fixed in version 1.2.15-7. For the unstable distribution (sid), this problem has been fixed in version 2.0.13-1. We recommend that you upgrade your dovecot packages.

Debian Security Advisory

DSA-2252-1 dovecot -- programming error

Date Reported:
02 Jun 2011
Affected Packages:
dovecot
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 627443.
In Mitre's CVE dictionary: CVE-2011-1929.
More information:

It was discovered that the message header parser in the Dovecot mail server parsed NUL characters incorrectly, which could lead to denial of service through malformed mail headers.

The oldstable distribution (lenny) is not affected.

For the stable distribution (squeeze), this problem has been fixed in version 1.2.15-7.

For the unstable distribution (sid), this problem has been fixed in version 2.0.13-1.

We recommend that you upgrade your dovecot packages.