]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH] lib-imap-urlauth: Fix leaking uninitialized memory into client error message
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Wed, 6 May 2026 14:53:41 +0000 (14:53 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
imap_urlauth_fetch_parsed() called imap_msgpart_url_open_mailbox() with
client_error_r and then, on the ret==0 (mailbox-not-found) branch,
formatted a separate uninitialized local "error" pointer with
t_strdup_printf("Invalid URLAUTH: %s", error). The %s read process
stack memory until a NUL byte and sent it to the authenticated IMAP
client inside the "* NO Failed to fetch URLAUTH ..." response.

Broken by bb193c273e63ffa42c5c0b51ecd8860398e3beab

Gbp-Pq: Name 0001-lib-imap-urlauth-Fix-leaking-uninitialized-memory-in.patch

src/lib-imap-urlauth/imap-urlauth.c

index 3cdcc21bb6b0029538d3d588a444d7570fcbf1fc..21f4520a93342dec11f9a6d9c7f95a5c7db2d417 100644 (file)
@@ -513,7 +513,8 @@ int imap_urlauth_fetch_parsed(struct imap_urlauth_context *uctx,
        }
 
        if ((ret = imap_msgpart_url_open_mailbox(mpurl, &box, error_code_r,
-                                                client_error_r)) < 0) {
+                                                &error)) < 0) {
+               *client_error_r = t_strdup_printf("Invalid URLAUTH: %s", error);
                imap_msgpart_url_free(&mpurl);
                return -1;
        }