PT-2006-7587 · Mono+2 · Mono-Web+16

Timo Sirainen

·

Published

1970-01-01

·

Updated

2018-10-17

·

CVE-2006-5973

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dovecot versions 1.0test53 through 1.0.rc14 mono-core-32bit (affected versions not specified) mono-core (affected versions not specified) mono-core-x86 (affected versions not specified) mono-data (affected versions not specified) mono-data-sqlite (affected versions not specified) mono-data-sybase (affected versions not specified) mono-devel (affected versions not specified) mono-extras (affected versions not specified) mono-ikvm (affected versions not specified) mono-jscript (affected versions not specified) mono-locale-extras (affected versions not specified) mono-nunit (affected versions not specified) mono-web (affected versions not specified) mono-winforms (affected versions not specified)
Description The issue involves multiple vulnerabilities in various packages of the SUSE Linux Enterprise and openSUSE operating systems, including mono and Dovecot. These vulnerabilities can lead to a disruption of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely. In the case of Dovecot, an off-by-one buffer overflow can occur when index files are used and mmap disable is set to "yes," allowing remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
Recommendations For Dovecot versions 1.0test53 through 1.0.rc14, consider updating to a version outside of this range to mitigate the risk. For mono-core-32bit, restrict access to vulnerable components until a patch is available. For mono-core, consider disabling vulnerable functions until a patch is available. For mono-core-x86, avoid using vulnerable parameters in affected API endpoints until the issue is resolved. For mono-data, restrict access to the vulnerable module to minimize the risk of exploitation. For mono-data-sqlite, consider disabling the vulnerable sqlite function until a patch is available. For mono-data-sybase, restrict access to the vulnerable sybase module to minimize the risk of exploitation. For mono-devel, avoid using vulnerable parameters in affected API endpoints until the issue is resolved. For mono-extras, consider disabling vulnerable functions until a patch is available. For mono-ikvm, restrict access to vulnerable components until a patch is available. For mono-jscript, avoid using vulnerable parameters in affected API endpoints until the issue is resolved. For mono-locale-extras, restrict access to the vulnerable module to minimize the risk of exploitation. For mono-nunit, consider disabling the vulnerable nunit function until a patch is available. For mono-web, restrict access to vulnerable components until a patch is available. For mono-winforms, avoid using vulnerable parameters in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability in the other affected packages.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04635
BDU:2015-04636
BDU:2015-04637
BDU:2015-04638
BDU:2015-04639
BDU:2015-04640
BDU:2015-04641
BDU:2015-04642
BDU:2015-04643
BDU:2015-04644
BDU:2015-04645
BDU:2015-04646
BDU:2015-04647
BDU:2015-04648
BDU:2015-04649
BDU:2015-04650
BDU:2015-04651
BDU:2015-04925
BDU:2015-04926
CVE-2006-5973

Affected Products

Dovecot
Suse Linux Enterprise
Mono-Core
Mono-Core-32Bit
Mono-Core-X86
Mono-Data
Mono-Data-Sqlite
Mono-Data-Sybase
Mono-Devel
Mono-Extras
Mono-Ikvm
Mono-Jscript
Mono-Locale-Extras
Mono-Nunit
Mono-Web
Mono-Winforms
Opensuse