Commit Graph

5 Commits

Author SHA256 Message Date
572e38fe4f - pull backport patch dovecot-2.3.0.1-over-quota-lmtp-crash.patch
OBS-URL: https://build.opensuse.org/package/show/server:mail/dovecot23?expand=0&rev=7
2018-03-06 18:03:27 +00:00
355adda1ff - update to 2.3.0.1
* CVE-2017-15130: TLS SNI config lookups may lead to excessive
    memory usage, causing imap-login/pop3-login VSZ limit to be
    reached and the process restarted. This happens only if Dovecot
    config has local_name { } or local { } configuration blocks and
    attacker uses randomly generated SNI servernames.
  * CVE-2017-14461: Parsing invalid email addresses may cause a
    crash or leak memory contents to attacker. For example, these
    memory contents might contain parts of an email from another
    user if the same imap process is reused for multiple users.
    First discovered by Aleksandar Nikolic of Cisco Talos.
    Independently also discovered by "flxflndy" via HackerOne.
  * CVE-2017-15132: Aborted SASL authentication leaks memory in
    login process.
  * Linux: Core dumping is no longer enabled by default via
    PR_SET_DUMPABLE, because this may allow attackers to bypass
    chroot/group restrictions. Found by cPanel Security Team.
    Nowadays core dumps can be safely enabled by using "sysctl -w
    fs.suid_dumpable=2". If the old behaviour is wanted, it can
    still be enabled by setting:
    import_environment=$import_environment PR_SET_DUMPABLE=1
  - imap-login with SSL/TLS connections may end up in infinite loop

OBS-URL: https://build.opensuse.org/package/show/server:mail/dovecot23?expand=0&rev=6
2018-03-06 13:53:55 +00:00
4ea5f55590 Accepting request 559954 from home:jengelh:branches:server:mail
- Replace %__-type macro indirections.
  Replace xargs rm by built in -delete of find(1).
- Run ldconfig directly via %post -p.
- Check for users in %pre before creating them, and do not suppress
  errors about it.

OBS-URL: https://build.opensuse.org/request/show/559954
OBS-URL: https://build.opensuse.org/package/show/server:mail/dovecot23?expand=0&rev=3
2018-01-09 13:47:47 +00:00
c8ae08e7fc - backport 321a39be974deb2e7eff7b2a509a3ee6ff2e5ae1.patch
fixes crash with imap sieve

OBS-URL: https://build.opensuse.org/package/show/server:mail/dovecot23?expand=0&rev=2
2017-12-25 18:51:39 +00:00
0235820ac5 Accepting request 559675 from home:darix:playground
new package of 2.3.0

OBS-URL: https://build.opensuse.org/request/show/559675
OBS-URL: https://build.opensuse.org/package/show/server:mail/dovecot23?expand=0&rev=1
2017-12-24 02:20:56 +00:00