]> dgit.raspbian.org Git - dovecot.git/commit
[PATCH] lib-imap-urlauth: Fix leaking uninitialized memory into client error message
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Wed, 6 May 2026 14:53:41 +0000 (14:53 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
commita768fa183f136ac8dd32e201736440f089f2ec8a
tree4fd9ae3a15322165455dcabdb71c451a350c3a6d
parent9c10ea7ba24a4ba102273abfe374fc267431d52c
[PATCH] lib-imap-urlauth: Fix leaking uninitialized memory into client error message

imap_urlauth_fetch_parsed() called imap_msgpart_url_open_mailbox() with
client_error_r and then, on the ret==0 (mailbox-not-found) branch,
formatted a separate uninitialized local "error" pointer with
t_strdup_printf("Invalid URLAUTH: %s", error). The %s read process
stack memory until a NUL byte and sent it to the authenticated IMAP
client inside the "* NO Failed to fetch URLAUTH ..." response.

Broken by bb193c273e63ffa42c5c0b51ecd8860398e3beab

Gbp-Pq: Name 0001-lib-imap-urlauth-Fix-leaking-uninitialized-memory-in.patch
src/lib-imap-urlauth/imap-urlauth.c