Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.59525
Category:Fedora Local Security Checks
Title:Fedora Core 5 FEDORA-2007-493 (dovecot)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to dovecot
announced via advisory FEDORA-2007-493.

Dovecot is an IMAP server for Linux/UNIX-like systems, written with security
primarily in mind. It also contains a small POP3 server. It supports mail
in either of maildir or mbox formats.


* Fri Mar 2 2007 Tomas Janousek - 1.0-0.beta8.4.fc5
- a little master login fix (#224925)
- fix for CVE-2007-2231 (#238440)
* Thu Dec 21 2006 Tomas Janousek - 1.0-0.beta8.3.fc5
- fixed default paths in the example mkcert.sh to match configuration
defaults (fixes #183151)
- fixed off by one (#216508, CVE-2006-5973)
* Thu Jun 8 2006 Petr Rockai - 1.0-0.beta8.2.fc5
- bring FC-5 branch up to date with the rawhide one (bugfixes only)
- should fix non-working pop3 in default installation
* Thu Jun 8 2006 Petr Rockai - 1.0-0.beta8.2
- put back pop3_uidl_format default that got lost
in the beta2->beta7 upgrade (would cause pop3 to not work
at all in many situations)
* Thu May 4 2006 Petr Rockai - 1.0-0.beta8.1
- upgrade to latest upstream beta release (beta8)
- contains a security fix in mbox handling
* Thu May 4 2006 Petr Rockai - 1.0-0.beta7.1
- upgrade to latest upstream beta release
- fixed BR 173048
* Fri Mar 17 2006 Petr Rockai - 1.0-0.beta2.8
- fix sqlite detection in upstream configure checks, second part
of #182240

Solution: Apply the appropriate updates.

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/


This update can be installed with the 'yum' update program. Use 'yum update
package-name' at the command line. For more information, refer to 'Managing
Software with yum,' available at http://fedora.redhat.com/docs/yum/.


http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2007-493

Risk factor : Medium

CVSS Score:
5.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-2231
BugTraq ID: 23552
http://www.securityfocus.com/bid/23552
Bugtraq: 20070418 rPSA-2007-0074-1 dovecot (Google Search)
http://www.securityfocus.com/archive/1/466168/100/0/threaded
Debian Security Information: DSA-1359 (Google Search)
http://www.debian.org/security/2007/dsa-1359
http://dovecot.org/list/dovecot-cvs/2007-March/008488.html
http://dovecot.org/list/dovecot-news/2007-March/000038.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10995
http://www.redhat.com/support/errata/RHSA-2008-0297.html
http://secunia.com/advisories/25072
http://secunia.com/advisories/30342
SuSE Security Announcement: SUSE-SR:2007:008 (Google Search)
http://www.novell.com/linux/security/advisories/2007_8_sr.html
http://www.ubuntu.com/usn/usn-487-1
http://www.vupen.com/english/advisories/2007/1452
XForce ISS Database: dovecot-mboxstorage-directory-traversal(34082)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34082
Common Vulnerability Exposure (CVE) ID: CVE-2006-5973
BugTraq ID: 21183
http://www.securityfocus.com/bid/21183/info
Bugtraq: 20061119 Dovecot IMAP/POP3 server: Off-by-one buffer overflow (Google Search)
http://www.securityfocus.com/archive/1/452081/100/0/threaded
http://dovecot.org/list/dovecot-news/2006-November/000023.html
http://dovecot.org/pipermail/dovecot-news/2006-November/000024.html
http://securitytracker.com/id?1017288
http://secunia.com/advisories/23007
http://secunia.com/advisories/23150
http://secunia.com/advisories/23172
http://secunia.com/advisories/23213
SuSE Security Announcement: SUSE-SA:2006:073 (Google Search)
http://www.novell.com/linux/security/advisories/2006_73_mono.html
http://www.ubuntu.com/usn/usn-387-1
http://www.vupen.com/english/advisories/2006/4614
XForce ISS Database: dovecot-indexcache-bo(30433)
https://exchange.xforce.ibmcloud.com/vulnerabilities/30433
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.