diff options
| -rw-r--r-- | meta-networking/recipes-support/dovecot/dovecot/0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch | 30 | ||||
| -rw-r--r-- | meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb | 1 |
2 files changed, 31 insertions, 0 deletions
diff --git a/meta-networking/recipes-support/dovecot/dovecot/0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch b/meta-networking/recipes-support/dovecot/dovecot/0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch new file mode 100644 index 0000000000..5580cd409f --- /dev/null +++ b/meta-networking/recipes-support/dovecot/dovecot/0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch | |||
| @@ -0,0 +1,30 @@ | |||
| 1 | From bd9d2fe7da833f0e4705a8280efc56930371806b Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Aki Tuomi <aki.tuomi@open-xchange.com> | ||
| 3 | Date: Wed, 6 May 2020 13:40:36 +0300 | ||
| 4 | Subject: [PATCH 1/3] auth: mech-rpa - Fail on zero len buffer | ||
| 5 | |||
| 6 | --- | ||
| 7 | src/auth/mech-rpa.c | 2 +- | ||
| 8 | 1 file changed, 1 insertion(+), 1 deletion(-) | ||
| 9 | |||
| 10 | Signed-off-by: Sana Kazi <Sana.Kazi@kpit.com> | ||
| 11 | |||
| 12 | CVE: CVE-2020-12674 | ||
| 13 | Upstream-Status: Backport [http://archive.ubuntu.com/ubuntu/pool/main/d/dovecot/dovecot_2.2.33.2-1ubuntu4.7.debian.tar.xz] | ||
| 14 | Comment: No change in any hunk | ||
| 15 | |||
| 16 | diff --git a/src/auth/mech-rpa.c b/src/auth/mech-rpa.c | ||
| 17 | index 08298ebdd6..2de8705b4f 100644 | ||
| 18 | --- a/src/auth/mech-rpa.c | ||
| 19 | +++ b/src/auth/mech-rpa.c | ||
| 20 | @@ -224,7 +224,7 @@ rpa_read_buffer(pool_t pool, const unsigned char **data, | ||
| 21 | return 0; | ||
| 22 | |||
| 23 | len = *p++; | ||
| 24 | - if (p + len > end) | ||
| 25 | + if (p + len > end || len == 0) | ||
| 26 | return 0; | ||
| 27 | |||
| 28 | *buffer = p_malloc(pool, len); | ||
| 29 | -- | ||
| 30 | 2.11.0 | ||
diff --git a/meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb b/meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb index e36e51c283..29905196b6 100644 --- a/meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb +++ b/meta-networking/recipes-support/dovecot/dovecot_2.2.36.4.bb | |||
| @@ -25,6 +25,7 @@ SRC_URI = "http://dovecot.org/releases/2.2/dovecot-${PV}.tar.gz \ | |||
| 25 | file://0013-lib-mail-Fix-parse_too_many_nested_mime_parts.patch \ | 25 | file://0013-lib-mail-Fix-parse_too_many_nested_mime_parts.patch \ |
| 26 | file://buffer_free_fix.patch \ | 26 | file://buffer_free_fix.patch \ |
| 27 | file://0002-lib-ntlm-Check-buffer-length-on-responses.patch \ | 27 | file://0002-lib-ntlm-Check-buffer-length-on-responses.patch \ |
| 28 | file://0001-auth-mech-rpa-Fail-on-zero-len-buffer.patch \ | ||
| 28 | " | 29 | " |
| 29 | 30 | ||
| 30 | SRC_URI[md5sum] = "66c4d71858b214afee5b390ee602dee2" | 31 | SRC_URI[md5sum] = "66c4d71858b214afee5b390ee602dee2" |
