From: Timo Sirainen Date: Wed, 6 May 2026 14:53:41 +0000 (+0000) Subject: [PATCH] lib-imap-urlauth: Fix leaking uninitialized memory into client error message X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~5 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=a768fa183f136ac8dd32e201736440f089f2ec8a;p=dovecot.git [PATCH] lib-imap-urlauth: Fix leaking uninitialized memory into client error message imap_urlauth_fetch_parsed() called imap_msgpart_url_open_mailbox() with client_error_r and then, on the ret==0 (mailbox-not-found) branch, formatted a separate uninitialized local "error" pointer with t_strdup_printf("Invalid URLAUTH: %s", error). The %s read process stack memory until a NUL byte and sent it to the authenticated IMAP client inside the "* NO Failed to fetch URLAUTH ..." response. Broken by bb193c273e63ffa42c5c0b51ecd8860398e3beab Gbp-Pq: Name 0001-lib-imap-urlauth-Fix-leaking-uninitialized-memory-in.patch --- diff --git a/src/lib-imap-urlauth/imap-urlauth.c b/src/lib-imap-urlauth/imap-urlauth.c index 3cdcc21..21f4520 100644 --- a/src/lib-imap-urlauth/imap-urlauth.c +++ b/src/lib-imap-urlauth/imap-urlauth.c @@ -513,7 +513,8 @@ int imap_urlauth_fetch_parsed(struct imap_urlauth_context *uctx, } if ((ret = imap_msgpart_url_open_mailbox(mpurl, &box, error_code_r, - client_error_r)) < 0) { + &error)) < 0) { + *client_error_r = t_strdup_printf("Invalid URLAUTH: %s", error); imap_msgpart_url_free(&mpurl); return -1; }