imap_urlauth_fetch_parsed() called imap_msgpart_url_open_mailbox() with
client_error_r and then, on the ret==0 (mailbox-not-found) branch,
formatted a separate uninitialized local "error" pointer with
t_strdup_printf("Invalid URLAUTH: %s", error). The %s read process
stack memory until a NUL byte and sent it to the authenticated IMAP
client inside the "* NO Failed to fetch URLAUTH ..." response.
Broken by
bb193c273e63ffa42c5c0b51ecd8860398e3beab
Gbp-Pq: Name 0001-lib-imap-urlauth-Fix-leaking-uninitialized-memory-in.patch
}
if ((ret = imap_msgpart_url_open_mailbox(mpurl, &box, error_code_r,
- client_error_r)) < 0) {
+ &error)) < 0) {
+ *client_error_r = t_strdup_printf("Invalid URLAUTH: %s", error);
imap_msgpart_url_free(&mpurl);
return -1;
}