Kotsi e kholo ho seva sa Dovecot IMAP

В litokollo tsa ho lokisa Li-server tsa POP3/IMAP4 Dovecot 2.3.7.2 le 2.2.36.4, hammoho le tlatsetsong Pigeonhole 0.5.7.2 le 0.4.24.2 , felisitsoe bofokodi bo boholo (CVE-2019-11500), e o lumellang hore o ngole data ho feta buffer e fanoeng ka ho romella kopo e entsoeng ka mokhoa o ikhethileng ka IMAP kapa ManageSieve protocols.

Bothata bo ka sebelisoa molemong oa pele ho netefatso. Ts'ebetso ea ts'ebetso ha e so lokisoe, empa baetsi ba Dovecot ha ba fane ka monyetla oa ho sebelisa bofokoli ho hlophisa litlhaselo tsa ts'ebetso ea khoutu e hole ho sistimi kapa ho hlakola data ea lekunutu. Basebelisi bohle ba khothaletsoa ho kenya liapdeite hang-hang (Debian, Fedora, Arch Linux, Botho, sebelisa, RHEL, FreeBSD).

Kotsi e teng ho li-protocol tsa IMAP le ManageSieve 'me e bakoa ke ts'ebetso e fosahetseng ea litlhaku tse sa sebetseng ha ho arola lintlha ka har'a likhoele tse qotsitsoeng. Bothata bo finyelloa ka ho ngola lintlha tse ling ho lintho tse bolokiloeng ka ntle ho buffer e fanoeng (ho fihla ho 8 KB e ka ngoloa sethaleng pele ho netefatso, le ho fihla ho 64 KB ka mor'a ho netefatsa).

Ka maikutlo Ho ea ka baenjiniere ba tsoang Red Hat, ho sebelisa bothata bakeng sa litlhaselo tsa 'nete ho thata hobane mohlaseli a ke ke a laola boemo ba ho qoelisoa ha data ka mokhoa o feteletseng ka har'a qubu. Ha a arabela, ho hlalosoa maikutlo a hore tšobotsi ena e thatafatsa tlhaselo feela, empa ha e kenye ts'ebetsong ea eona - mohlaseli a ka pheta boiteko ba ho tlatlapa ka makhetlo a mangata ho fihlela a kena sebakeng sa ho sebetsa ka har'a qubu.

Source: opennet.ru

Eketsa ka tlhaloso