From 99d7c3bd24d8dd3a575e82ef643a1c10300383f37256b121fbc8d141aa5d02fc Mon Sep 17 00:00:00 2001 From: Marcus Rueckert Date: Mon, 18 May 2020 16:29:39 +0000 Subject: [PATCH] - add bugnumbers OBS-URL: https://build.opensuse.org/package/show/server:mail/dovecot23?expand=0&rev=72 --- dovecot23.changes | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/dovecot23.changes b/dovecot23.changes index c67ca45..5c183fa 100644 --- a/dovecot23.changes +++ b/dovecot23.changes @@ -4,12 +4,13 @@ Mon May 18 14:04:52 UTC 2020 - Michael Ströder - update to 2.3.10.1 with security fixes for * CVE-2020-10957: lmtp/submission: A client can crash the server by sending a NOOP command with an invalid string parameter. + (boo#1171457) * CVE-2020-10958: lmtp/submission: Sending many invalid or unknown commands can cause the server to access freed memory, which can lead - to a server crash. + to a server crash. (boo#1171458) * CVE-2020-10967: lmtp/submission: Issuing the RCPT command with an address that has the empty quoted string as local-part causes the - lmtp service to crash. + lmtp service to crash. (boo#1171456) ------------------------------------------------------------------- Wed Apr 29 21:25:30 UTC 2020 - Marcus Rueckert