]> rtime.felk.cvut.cz Git - coffee/buildroot.git/blob - package/dovecot/0002-lib-auth-Fix-memory-leak-in-auth_client_request_abor.patch
dovecot: add upstream security fix for CVE-2017-15132
[coffee/buildroot.git] / package / dovecot / 0002-lib-auth-Fix-memory-leak-in-auth_client_request_abor.patch
1 From 1a29ed2f96da1be22fa5a4d96c7583aa81b8b060 Mon Sep 17 00:00:00 2001
2 From: Timo Sirainen <timo.sirainen@dovecot.fi>
3 Date: Mon, 18 Dec 2017 16:50:51 +0200
4 Subject: [PATCH] lib-auth: Fix memory leak in auth_client_request_abort()
5
6 This caused memory leaks when authentication was aborted. For example
7 with IMAP:
8
9 a AUTHENTICATE PLAIN
10 *
11
12 Broken by 9137c55411aa39d41c1e705ddc34d5bd26c65021
13
14 Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
15 ---
16  src/lib-auth/auth-client-request.c | 1 +
17  1 file changed, 1 insertion(+)
18
19 diff --git a/src/lib-auth/auth-client-request.c b/src/lib-auth/auth-client-request.c
20 index 480fb42b3..046f7c307 100644
21 --- a/src/lib-auth/auth-client-request.c
22 +++ b/src/lib-auth/auth-client-request.c
23 @@ -186,6 +186,7 @@ void auth_client_request_abort(struct auth_client_request **_request)
24  
25         auth_client_send_cancel(request->conn->client, request->id);
26         call_callback(request, AUTH_REQUEST_STATUS_ABORT, NULL, NULL);
27 +       pool_unref(&request->pool);
28  }
29  
30  unsigned int auth_client_request_get_id(struct auth_client_request *request)
31 -- 
32 2.11.0
33