Accepting request 1194886 from server:mail

OBS-URL: https://build.opensuse.org/request/show/1194886
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/dovecot23?expand=0&rev=54
This commit is contained in:
Ana Guerrero 2024-08-20 14:15:09 +00:00 committed by Git OBS Bridge
commit d84d61e74f
10 changed files with 65 additions and 43 deletions

View File

@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:0377db284b620723de060431115fb2e7791e1df4321411af718201d6925c4692
size 1956404

View File

@ -0,0 +1,17 @@
-----BEGIN PGP SIGNATURE-----
iQJLBAABCgA1FiEEK+dKqz7nVN+5yA0zGKNIru1AnaEFAma8fsIXHGRvdmVjb3Qt
Y2VAZG92ZWNvdC5vcmcACgkQGKNIru1AnaFbpA//Tdg+pLQsXCMQx6oVtk0QN/MX
838FRT/fJZZtyCz+ldiTfCdYBxOk5FHhFHaMZV4ibZBCSmQVxr2SOAb0yEWXXort
50XC2T0J5XOxgBuQI0Q4ltOzl++ghExYmp+aAO7I5XjWOOn4g+nOguQdmTvVbOq4
JwIgtnK9iK/6/phMgu0bdd5SGOJsjoRsw5mBM0/CkZ0kJ9RzSKJ6mZc7g6KdZLRF
8o+fBq/Ioo5snPNCsWx8Ms6T7hg/TTxyc2g+4PF7jMcn2zPhpWiQ3v/nGmhppPsE
Wz2+/folqP0avgG2McGPDUXDV9D7EhVnZ87julZd+HAAAPMi7duxc6Ow2/8FvJBW
xvtNjXs7hwUxp0kpn5JfAAohljVABzDIQgNptmr5VKA4jYtIf02F3rwfWIUaRrpl
xnFrIWOU7+6ED7ylQew5TuUBjguQBrt0O6ppu0o2f3R0LkFelVWJfG0H5EH0HN9v
1+91JYdbmUOVphRXfXH5qi1BSuYR267O8zg5mA/22jti0TJ+rrWUy5FVv1SVTlh2
VBYhK2VYayUaEttzwmUTQkgbLWA7RcPLVpqCS/FlgJAwiskxiwJCxe9gZxf+qVVk
CZOmquC26UiGXATlhmf5k8UOHBsnVCBnRzuE9w15wXUIs4OCIhNiPOct710+RcfZ
mXkDwgI2e0uXwun3Qt8=
=6oIY
-----END PGP SIGNATURE-----

View File

@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:1ca71d2659076712058a72030288f150b2b076b0306453471c5261498d3ded27
size 1955945

View File

@ -1,17 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQJLBAABCgA1FiEEK+dKqz7nVN+5yA0zGKNIru1AnaEFAmUD/LgXHGRvdmVjb3Qt
Y2VAZG92ZWNvdC5vcmcACgkQGKNIru1AnaEOrw//XMtJvAS4s+6VIJ1faAQFztKS
8lo3e6dd+EHKEMz70mXu/5tdEQS7JkiN+9O6CbjNY0+/zHmYmXXXiVCvldpSqDhe
9c2mIOeAg0C2EVY5Qf/RJ940ByF4Kd/ulUY6exaUycJkUccNEYgBGVWOnIwNDlV/
hCLlJy1540nApo7ys9XVh3+WO2I3a8xVm5cRug6j0FD93rhmWc7dpeCe40j7xz0q
pMKGbGlQueRgeZ1NO7Qp+9ZIVyy9xIZIuNt13GwhD830ObpE2aGFfW6yxdmIRrgK
/wIp+fzdMbPLNbtmCdh1NXz88zC6KbEII1rHaL/KejK7XtOkzR06yOJYr/tgJN+s
BnWGQbCAVfBUMWdnvzgs0nTgzqattlXPqoD1v3TkMYXKYcf9Tow9RGNaDk0DXGCH
bx3+oBkfjUEvxDU7td4F7DMVjBQZpwhNA/TiGraabtPQKfR4zFcYQUyw3T3G+Rv3
PZ32mTmC9TTN5blTxamvsrK2SpFT3uXm1ch019228pul0DtcvjcdZFgkyWl3I0Xy
Na/GEPlVodVVTx0cAGbUCeS6Ja3UG9Le4KjfYOEQ8gBeo5dD4/hrs0ZXHBri7XcW
0ackeYB4JrSDALumjbHTRL+vo9d0FbtpkxBq9RMXM/xVqMpzfSo3Ac3bViBh05pX
BXYU8Uy5LU0VjN7FpOI=
=a386
-----END PGP SIGNATURE-----

3
dovecot-2.3.21.1.tar.gz Normal file
View File

@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:2d90a178c4297611088bf7daae5492a3bc3d5ab6328c3a032eb425d2c249097e
size 7842044

View File

@ -0,0 +1,17 @@
-----BEGIN PGP SIGNATURE-----
iQJLBAABCgA1FiEEK+dKqz7nVN+5yA0zGKNIru1AnaEFAma8frUXHGRvdmVjb3Qt
Y2VAZG92ZWNvdC5vcmcACgkQGKNIru1AnaHesA//QG3U92zq5vmWLoEC7G8nKbT7
JUYthTqG4j2wgEngdcZmylKo4dbXvbEljf9PdTfFAJJbwKDaOgKedwykQo+xIGwO
y8Xkcs8iyB4Sv9boZp4aIPSCPr5zLE81dZrjy7UNxOyNxQKkcr092HhLxLhU3ktJ
Kpjkr6yVdgDVmu48jvePhxTVlH/whdN/5DWxfkUjp09xZRjTwSOqBaoQTyVgTvQv
HYVUsfzLHmeUjkasZ/piaHdZPq1fdtIMjmDVUkpyZcyQVEUABLOF1ahYCNIgQlrS
61roI3rI58P7YQAguhoNpvBvQGUflUp8UFhv1XDTVcHpEKQzBXv/SUX+H14vHfek
m8qX4gs/WKwIajH7dvdBC2Rz2ApVfXPrBLZRNyOxjMI3OhGNfeCLKX/bQajltHmx
EP9eW60WYkfI3BlbnkIJDcRFFo1Wq1p97tQS/I+wct9tLtbokmOPJYGAsge/kWT3
iywTPopD3mTtcvtcK7eVs3u9OYOJPhAsyBk6ahlcQ+3niks1LeqMpaWG2QgvNUUo
se3zjMzVeC/FbWj5H9qJyp282xRce88CD0vzBLThRTR5OXIPujqOvsvJN7qFcpKi
6lenb26sDXYxLHEsDkRw8oQtk6jGOJh971X8Tr4S+RLmwo3hNZ9qZtYjs7h7485x
Iu/utjziOizSFIsy2Jk=
=8VHs
-----END PGP SIGNATURE-----

View File

@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:05b11093a71c237c2ef309ad587510721cc93bbee6828251549fc1586c36502d
size 7837242

View File

@ -1,17 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQJLBAABCgA1FiEEK+dKqz7nVN+5yA0zGKNIru1AnaEFAmUD/KAXHGRvdmVjb3Qt
Y2VAZG92ZWNvdC5vcmcACgkQGKNIru1AnaGv3Q//bB9M8lEVqTyljhPFphhNLJvj
zxh9U08nUOpOV9X+IfVX4PcorS5SqrPU45ohVmstLhMf6+ONHLWqE9GHFJrwsvtC
/aPdX5ZPQN7/H76hW9rD+m9ytCkKC+sH2tf4RR8IWtfVjF2cU+jRbMcGSJ2SbKS4
APOEMJgdtmh5vZTHMYCSv0+8+pi4LNm3pth6XbbneJ8cmoLlZ3kjUn63pb8atkwF
fhSNIMjb3ZKE4kJT+p01Q18DO5X4DQuPrjiuRPHLpe+PbsUYdu44Wuu+vsM/eSO2
RQ3C+uoFg2DfhwkjLxiiTli+bnKONUKpBae3ckG1GO6cBqtPuDEIea2dcPOjJ3Ga
Vpssy+iq7qvGIZDC5YPmdRH6O0k4r0ntTljFlpg2SW7afE2tC1ipadCcwOsF9dUZ
DDF89o+k8s0kl8486YTIeTSwGBWJCQJPzmdA8hBxCcVTvvo5G+N2xxX6ZL+wqG3Y
vV43n/Xvi4GkrOS7Rp+SOMGS5E4/+VB2udC3qm1s6cFm0bFVXMGwbzFnKqpcGaYX
UDmbZAkKA4pCkEdNJIz1QUpNtQnf1vGHaMeW+IAW5xPjKJ15/M+GPZ0yeqv2Gt6I
v1J0EM5ZkgNJ+9NU093QxORdXrTD7bDMa5yOv/7ih+9Cx4r9GhdgS/T/3LZIncrg
xpKXvK/XKM7RFMhOnz4=
=fueB
-----END PGP SIGNATURE-----

View File

@ -1,3 +1,25 @@
-------------------------------------------------------------------
Wed Aug 14 19:09:12 UTC 2024 - Arjen de Korte <suse+build@de-korte.org>
- update to 2.3.21.1 and pigeonhole 0.5.21.1
Dovecot 2.3.21.1
- CVE-2024-23184: A large number of address headers in email resulted
in excessive CPU usage. [boo#1229184]
- CVE-2024-23185: Abnormally large email headers are now truncated or
discarded, with a limit of 10MB on a single header and 50MB for all
the headers of all the parts of an email. [boo#1229183]
- oauth2: Dovecot would send client_id and client_secret as POST parameters
to introspection server. These need to be optionally in Basic auth
instead as required by OIDC specification.
- oauth2: JWT key type check was too strict.
- oauth2: JWT token audience was not validated against client_id as
required by OIDC specification.
- oauth2: XOAUTH2 and OAUTHBEARER mechanisms were not giving out
protocol specific error message on all errors. This broke OIDC discovery.
- oauth2: JWT aud validation was not performed if aud was missing
from token, but was configured on Dovecot.
-------------------------------------------------------------------
Mon Nov 6 15:58:22 UTC 2023 - Dominique Leuenberger <dimstar@opensuse.org>

View File

@ -17,11 +17,11 @@
Name: dovecot23
Version: 2.3.21
Version: 2.3.21.1
Release: 0
%define pkg_name dovecot
%define dovecot_version 2.3.21
%define dovecot_pigeonhole_version 0.5.21
%define dovecot_version 2.3.21.1
%define dovecot_pigeonhole_version 0.5.21.1
%define dovecot_branch 2.3
%define dovecot_pigeonhole_source_dir %{pkg_name}-%{dovecot_branch}-pigeonhole-%{dovecot_pigeonhole_version}
%define dovecot_pigeonhole_docdir %{_docdir}/%{pkg_name}/dovecot-pigeonhole