summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorsana kazi <sanakazisk19@gmail.com>2021-12-03 17:59:58 +0530
committerArmin Kuster <akuster808@gmail.com>2021-12-03 12:23:42 -0800
commitfba8ff0d916383ce65045c36ba4c805b5a2dfcc0 (patch)
tree1f0c35398eeba5be5c18b8f0dbcfb0ff5b1612b6
parent7804c8e5bd2975c9829e1667ab1954373a3ede48 (diff)
downloadmeta-openembedded-fba8ff0d916383ce65045c36ba4c805b5a2dfcc0.tar.gz
dovecot: Fix CVE-2020-12674
Added patch for CVE-2020-12674 Link: http://archive.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot_2.2.33.2-1ubuntu4.7.debian.tar.xz Signed-off-by: Sana Kazi <Sana.Kazi@kpit.com> Signed-off-by: Sana Kazi <sanakazisk19@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
-rw-r--r--meta-networking/recipes-support/dovecot/dovecot/0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch30
-rw-r--r--meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb1
2 files changed, 31 insertions, 0 deletions
diff --git a/meta-networking/recipes-support/dovecot/dovecot/0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch b/meta-networking/recipes-support/dovecot/dovecot/0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch
new file mode 100644
index 000000000..5580cd409
--- /dev/null
+++ b/meta-networking/recipes-support/dovecot/dovecot/0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch
@@ -0,0 +1,30 @@
1From bd9d2fe7da833f0e4705a8280efc56930371806b Mon Sep 17 00:00:00 2001
2From: Aki Tuomi <aki.tuomi@open-xchange.com>
3Date: Wed, 6 May 2020 13:40:36 +0300
4Subject: [PATCH 1/3] auth: mech-rpa - Fail on zero len buffer
5
6---
7 src/auth/mech-rpa.c | 2 +-
8 1 file changed, 1 insertion(+), 1 deletion(-)
9
10Signed-off-by: Sana Kazi <Sana.Kazi@kpit.com>
11
12CVE: CVE-2020-12674
13Upstream-Status: Backport [http://archive.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot_2.2.33.2-1ubuntu4.7.debian.tar.xz]
14Comment: No change in any hunk
15
16diff --git a/src/auth/mech-rpa.c b/src/auth/mech-rpa.c
17index 08298ebdd6..2de8705b4f 100644
18--- a/src/auth/mech-rpa.c
19+++ b/src/auth/mech-rpa.c
20@@ -224,7 +224,7 @@ rpa_read_buffer(pool_t pool, const unsigned char **data,
21 return 0;
22
23 len = *p++;
24- if (p + len > end)
25+ if (p + len > end || len == 0)
26 return 0;
27
28 *buffer = p_malloc(pool, len);
29--
302.11.0
diff --git a/meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb b/meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb
index e36e51c28..29905196b 100644
--- a/meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb
+++ b/meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb
@@ -25,6 +25,7 @@ SRC_URI = "http://dovecot.org/releases/2.2/dovecot-${PV}.tar.gz \
25 file://0013-lib-mail-Fix-parse_too_many_nested_mime_parts.patch \ 25 file://0013-lib-mail-Fix-parse_too_many_nested_mime_parts.patch \
26 file://buffer_free_fix.patch \ 26 file://buffer_free_fix.patch \
27 file://0002-lib-ntlm-Check-buffer-length-on-responses.patch \ 27 file://0002-lib-ntlm-Check-buffer-length-on-responses.patch \
28 file://0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch \
28 " 29 "
29 30
30SRC_URI[md5sum] = "66c4d71858b214afee5b390ee602dee2" 31SRC_URI[md5sum] = "66c4d71858b214afee5b390ee602dee2"