 > Fixes the following security issue:
 >  * CVE-2019-7524: Missing input buffer size validation leads into
 >    arbitrary buffer overflow when reading fts or pop3 uidl header
 >    from Dovecot index. Exploiting this requires direct write access to
 >    the index files.

Committed to 2019.02.x (and the corresponding dovecot-pigeonhole bump), thanks.

