In POP3/IMAP4 servers 2.3.7.2 and 2.2.36.4, as well as in addition , fixed (), which allows data to be written outside the allocated buffer through sending a specially crafted request over the IMAP or ManageSieve protocols.
The issue can be exploited at the stage before authentication. A working exploit has not yet been prepared, but Dovecot developers do not rule out the possibility of using the vulnerability to carry out remote code execution attacks in the system or to leak confidential data. All users are strongly recommended to urgently install updates (, , , , , , ).
The vulnerability exists in the IMAP and ManageSieve protocol parsers and is caused by improper handling of null characters during the parsing of data within quoted strings. The problem allows arbitrary data to be written to objects stored beyond allocated buffer limits (up to 8 KB before authentication and up to 64 KB after authentication).
According to Engineers from Red Hat note that exploiting the problem for real attacks is complicated by the fact that the attacker cannot control the position of arbitrary data overwrites in the heap. It is suggested that this feature significantly complicates the attack but does not exclude its execution — the attacker can repeatedly attempt exploitation until they hit the working area in the heap.
Source: opennet.ru
