Summary
The remote host is missing an update to dovecot
announced via advisory FEDORA-2009-9559.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update dovecot' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-9559
Insight
Update Information:
dovecot-sieve updated to 1.1.7
It is derived from CMU sieve used by cyrus-imapd and was affected by CVE-2009-2632 too.
See upstream announcement for further details:
http://dovecot.org/list/dovecot-news/2009-September/000135.html
ChangeLog:
* Mon Sep 14 2009 Michal Hlavinka - 1:1.1.18-2
- dovecot-sieve updated to 1.1.7
- fixes bug similar to CVE-2009-2632 (buffer overflow) * Wed Jul 29 2009 Michal Hlavinka - 1:1.1.18-1
- updated to 1.1.18
- Maildir++ quota: Quota was sometimes updated wrong when it was being recalculated.
- Searching quoted-printable message body internally converted _ characters to spaces and didn't match search keys with _.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-2632 -
CVSS Base Score: 4.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities